Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c4f168876413e5c…

MALICIOUS

PDF

46.8 KB Created: 2020-10-31 16:22:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: eab4ca47c502da78d75599c723e75eff SHA-1: dc7796adf819be31c7524b68f0bc7d45f943a8c8 SHA-256: 9c4f168876413e5cf3851e2cd2993ba2e791a0963d399a151db030dbed3dda2b
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/123?keyword=sharepoint+2010+excel+services+not+working In PDF document text
    • https://cdn-cms.f-static.net/uploads/4422912/normal_5f990af00f41b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365655/normal_5f8722de5af8b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4409992/normal_5f9d0702db9d4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365546/normal_5f8edf414b1b5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4382619/normal_5f9412a444dfb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369310/normal_5f8918779b668.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4415308/normal_5f947a6354e15.pdfIn PDF document text
    • http:///1cfa4f08faaf4b1384b5ae7b43d3688e/Conversion.Conversion.svcIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d292d592-ddcb-4e35-8fb3-930faa66de87/fapuwererodiwabazaxuf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eeb65923-5974-4aa7-aa1a-d1dd26e19f26/67054135401.pdfIn PDF document text
    • https://s3.amazonaws.com/mejifavo/wefitivof.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b0bdeb6-e236-4273-8685-ab6bdb8588de/63145916413.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7697cae1-d6cc-408f-a97d-1c6f9b0374fa/bemovular.pdfIn PDF document text
    • https://s3.amazonaws.com/memul/padujere.pdfIn PDF document text
    • https://s3.amazonaws.com/fowikorejodi/69756345941.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006a11.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6A11 5908 bytes
SHA-256: 7cd02add3069a72048aa24e6cba45b2164bf9039669ca75c120a0b07bdf7d0d2
font_01_sfnt_off00007e39.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7E39 2092 bytes
SHA-256: 13678a14b930e6d42e11b2ac41b13981c2c7f5938cc30cfb194ad51886f1f1dd
font_02_sfnt_off000087de.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x87DE 11180 bytes
SHA-256: b7eaf0e4edff51a7d088959b66a3b699fed047e0758782fa646f0ec3d744634a