Malicious PDF — malware analysis report

Static analysis result for SHA-256 af22f5c704c05cad…

MALICIOUS

PDF

84.1 KB Created: 2020-12-28 07:32:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 757a8222c7de803cccda4e121c6c2693 SHA-1: 12d30a9a252316b68ff61a56374c631ef6a255b1 SHA-256: af22f5c704c05cad0a9ce917740c8461706a2218527fa91d51943e48da9c501a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to a URL that appears to be part of a phishing lure related to a car sale. The ML classifier also strongly flagged this PDF as malicious. While no scripts were explicitly extracted, the PDF structure and the malicious URL suggest an attempt to redirect the user to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/123?utm_term=dodge+omni+for+sale+alberta
    • https://cdn-cms.f-static.net/uploads/4403264/normal_5f9897ee54a6e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/purawuma/mokamerovilezapovuxazurat.pdf
    • https://s3.amazonaws.com/wefemabeni/kufizojazakokekutenos.pdf
    • https://uploads.strikinglycdn.com/files/ac2767d0-eae1-4b0c-81ce-e9d2d4b8ecd7/xivosavurulu.pdf
    • https://s3.amazonaws.com/tuxutedi/3133414483.pdf
    • https://s3.amazonaws.com/bidivo/37509964717.pdf
    • https://s3.amazonaws.com/nuvukivaxiren/all_ugandan_gospel_music.pdf
    • https://s3.amazonaws.com/tezofuretejom/great_mills_high_school_md.pdf
    • https://s3.amazonaws.com/zifilobesumafi/42436134781.pdf
    • https://s3.amazonaws.com/novipaliwid/47488161210.pdf
    • https://s3.amazonaws.com/daniwodug/etv_annadata_telugu_song.pdf
    • https://uploads.strikinglycdn.com/files/c06d7f46-0249-49dd-9b5b-822873a8796e/lukeme.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00010f07.bin
b2e0e7efdc64da0fddce2bab8a9e67e7c94fa191ce1b630790afb71547d4d386
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10F07 22020 bytes
font_00_sfnt_off0000d82b.bin
888cbb1d41c9240e58e8e34b75342e3bcb5bf006a775fa92f2ab9f46fc0ead0d
pdf-font-stream PDF embedded font (sfnt) at offset 0xD82B 5152 bytes
font_01_sfnt_off0000e99d.bin
0f034342445d11fda4e84aaa4e1c5133983a7de5471f4e88a77aaf2ee57f344c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE99D 10956 bytes
font_03_sfnt_off00013522.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x13522 4324 bytes