Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6658b55479af546…

MALICIOUS

PDF

75.2 KB Created: 2020-12-20 18:58:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: fec983f5cfac71015e5325a9ec1bb285 SHA-1: 15edcd777f985d0b8b2c8f4a589c8b7661fc6656 SHA-256: a6658b55479af546d4435d2e5c1d3db2dce35b64180aed985e849358e37f5b1f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, indicating an attempt to phish or deliver malware. The ML classifier and ClamAV detection strongly support a malicious classification. Although no scripts were extracted, the presence of a malicious URL within the document body is a critical indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/strik?utm_term=how+to+connect+dac+to+integrated+amplifier In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4c82e6d49a06bb883108/1606372483753/vevawovelosudado.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/73f5392a-61b5-46ef-860d-681e35c99278/maxforce_ant_bait_home_depot.pdfIn PDF document text
    • https://s3.amazonaws.com/fonazuzixagizir/lake_chickamauga_fishing_report_2019.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/13610090-0326-4292-a9ce-fa760df27d0d/94401091268.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc52a78df132613bbd94fd8/t/5fc887d713f8d93bf2079b4c/1606977495740/zufigixikubivofozuzavoxi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2fa43ddf-c37a-4fdd-8c6b-76fa71176a41/rasenejaxijov.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/96edfc6c-552b-480b-b29f-e244391720f8/36777810950.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbfe895e5c7695ca99606f9/t/5fc86d80ec83506b047a2a0b/1606970756391/dragon_models_1_72_gemini_spacecraft.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/93fd98b8-8ad0-40a6-9460-4566905ad05b/guroliwaliraditenopunipa.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0e110403f5353fd95a22f/t/5fc2a670fa04221c71769dd2/1606592112687/95994760483.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f225a2f2-94ef-40e7-9094-fe213d532084/ganesexumo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bcb71a00-a7bd-40d8-9b21-3c4bb21c3b3c/geparodelazetigafisu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c7db067c-cda7-4bae-b221-9003342134bd/suvefugelukivumegumaben.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4bfe2cf5-2708-4d78-acef-8195a81a58d1/beginning_linux_programming_5th_edition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5d32fc93-17ad-48b9-a376-b7253d29d6f9/dudubur.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8f0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE8F0 5352 bytes
SHA-256: 5af3c758daf6828808e2e3d3c932b2360a8941a00988f1907a6fa62e0186c491
font_01_sfnt_off0000fb1f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB1F 10688 bytes
SHA-256: 5f49f63d8115d627de54d5abd2762106bb5f64febdbe15187bcefd3ca75bbba0