Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f49169610f36c32…

MALICIOUS

PDF

42.8 KB Created: 2020-10-26 18:10:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 30bd9616db6895d5fb35a66eb604d2d1 SHA-1: 98be9d677e5f948fdfdd3ec863ff301678d4f13c SHA-256: 9f49169610f36c3245c667a2b2c101b483e90920532c66f3eed74539e56e0c74
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://cctraff.ru/aws?keyword=bending+moment+experiment+report+pdf'. The document body, though heavily obfuscated, also contains this URL, suggesting it's intended to be clicked. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the presence of a malicious URL indicates a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?keyword=bending+moment+experiment+report+pdf
    • https://cdn-cms.f-static.net/uploads/4404514/normal_5f926cc5976e1.pdf
    • https://cdn-cms.f-static.net/uploads/4376099/normal_5f8c6ac95f9e4.pdf
    • https://dokakida.weebly.com/uploads/1/3/1/3/131380589/cdd1465cd2a15.pdf
    • https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/dd9b521.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0503/6651/3312/files/melted_ice_cream_truck.pdf
    • https://cdn.shopify.com/s/files/1/0499/8879/6575/files/osteomielitis_pada_anak.pdf
    • https://cdn.shopify.com/s/files/1/0486/2931/7790/files/adjustable_bungee_cords_walmart.pdf
    • https://cdn.shopify.com/s/files/1/0472/2763/3829/files/rinilufirakiz.pdf
    • https://s3.amazonaws.com/zikeko/taxibogonagozudabizedoma.pdf
    • https://s3.amazonaws.com/vuzufexarevima/89135838775.pdf
    • https://s3.amazonaws.com/lakadutof/12_hsc_biology_textbook_download.pdf
    • https://s3.amazonaws.com/tujeviwakirawu/deforestation_ppt.pdf
    • https://s3.amazonaws.com/sasufufa/wastewater_engineering_treatment_and_resource_recovery.pdf
    • https://s3.amazonaws.com/subud/44410580547.pdf
    • https://s3.amazonaws.com/leguvefu/games_workshop_lord_of_the_rings.pdf
    • https://uploads.strikinglycdn.com/files/9137c65c-9d39-4ec5-ae4e-94ff71c464c9/29980274489.pdf
    • https://uploads.strikinglycdn.com/files/38cbef04-1f5f-4be5-8c6e-1052ae9a7fc7/10527242652.pdf
    • https://uploads.strikinglycdn.com/files/2f6eca0b-eafd-4429-83a7-86184687a11d/vuwadovonilusukogu.pdf
    • https://uploads.strikinglycdn.com/files/9e16070b-b51f-432f-8989-d3f2dc5467aa/44862271157.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000678e.bin
86259ea9b4707004406d9e24ec2deb16b31974afcf798a8e06bc71e50780c233
pdf-font-stream PDF embedded font (sfnt) at offset 0x678E 5056 bytes
font_01_sfnt_off000078b6.bin
8680344db71af4526e825c92787a88400b3aec96c19ed890dfdc9b19120ceee3
pdf-font-stream PDF embedded font (sfnt) at offset 0x78B6 11004 bytes