Malicious PDF — malware analysis report

Static analysis result for SHA-256 a14ab29f28d157e9…

MALICIOUS

PDF

80.5 KB Created: 2020-12-22 01:15:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c0a2252201c12800b24e18575c9c2b30 SHA-1: 55910090a20dcf8b196b320943775128f1e2cc5c SHA-256: a14ab29f28d157e950e64437c2ae0b9ed14ab77ea5149dbfd4db355511f10df5
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://cctraff.ru/strik?utm_term=maze+pen+runner'. This URL is the primary indicator of malicious intent, likely serving as a lure for phishing or to download further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?utm_term=maze+pen+runner
    • https://cdn-cms.f-static.net/uploads/4382793/normal_5fbde0422a1cf.pdf
    • https://static.s123-cdn-static.com/uploads/4455659/normal_5fc9f8adaf32f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fazujo/10450576903.pdf
    • https://s3.amazonaws.com/zesotat/zifivepod.pdf
    • https://uploads.strikinglycdn.com/files/7b50a315-300a-427d-9057-0632acc2fcc4/98993129459.pdf
    • https://uploads.strikinglycdn.com/files/098dd1ae-a6ef-491e-a314-926342a2731b/pinoy_movies_2019_comedy.pdf
    • https://uploads.strikinglycdn.com/files/d165305c-b93f-4df3-935a-27910ed3a4fa/void_bastards_download.pdf
    • https://s3.amazonaws.com/tonisefoteka/vonoviwewukifeluzidazumo.pdf
    • https://s3.amazonaws.com/xulepiwa/80597219861.pdf
    • https://s3.amazonaws.com/tojazudibumogab/middle_of_the_night_paddy_chayefsky.pdf
    • https://uploads.strikinglycdn.com/files/f63b984b-9833-4817-a1c5-a01965abd7d0/pho_menu_reno.pdf
    • https://s3.amazonaws.com/dedinavesute/sorikiw.pdf
    • https://uploads.strikinglycdn.com/files/11222c61-cf93-4bd7-9c57-38f9a9869ce5/64618673496.pdf
    • https://s3.amazonaws.com/bewibiwat/zebuwediroj.pdf
    • https://s3.amazonaws.com/rodiligarexo/jonizevinalefijozezuba.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c8de.bin
4f36d13c343a5df1c68ae45d203d7b12a4863086366cf03d8c5717a8a0208ab4
pdf-font-stream PDF embedded font (sfnt) at offset 0xC8DE 10444 bytes
font_01_sfnt_off0000eb6d.bin
f4803a4ebb662a7abec9ef9afc53ba07caf7ea6b2551d111014c7fe0560c6262
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB6D 4660 bytes
font_02_sfnt_off0000fb65.bin
b737ddd214269408ef95c58a70d0eada370d8f23d71fd9d7bc3bffb99f25514e
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB65 10536 bytes
font_03_sfnt_off00011f75.bin
a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F75 16204 bytes