Malicious PDF — malware analysis report

Static analysis result for SHA-256 b29d74a13e152945…

MALICIOUS

PDF

55.0 KB Created: 2020-11-09 15:23:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 505a63cffee19d996f1961fc4871aa69 SHA-1: dfe1f021faa3cfaadb2f63d36fba08e90845267e SHA-256: b29d74a13e15294516a2cb61ba2182824f13a11bb875cdf45fb0c96f9034d7e8
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/strik?keyword=365+dni+movie+online+free+english+download In PDF document text
    • https://cdn-cms.f-static.net/uploads/4453902/normal_5fa48ae0c5095.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366003/normal_5f89420c4d4fd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4406466/normal_5f97e63148831.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378171/normal_5f9084d5766ce.pdfIn PDF document text
    • https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/cda762.pdfIn PDF document text
    • https://reninifovebomul.weebly.com/uploads/1/3/4/3/134361606/puxaxobi-dolumarurokukat.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/99a2f007-68f4-4b29-bed7-2b3a850d039a/15474071775.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/52a10a8b-5763-4658-92b3-e8e91c958c50/ejercicios_de_raices_cuadradas_3_eso.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8f6fcaa6-c418-4d87-8c83-6dea3a8c2300/2494835002.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/76baffdf-955e-42a1-986b-d53fb8f0e362/wosaripipiferuburu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/01990121-5b15-4eb3-8ed5-45b299f7bf97/dojitolu.pdfIn PDF document text
    • https://s3.amazonaws.com/xanebavifamopez/kuwuj.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb2041d3-2d5c-4c00-8c7f-8bc678dc1a16/desert_order_game_review.pdfIn PDF document text
    • https://s3.amazonaws.com/minaxigevani/cds_syllabus_upsc.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000058c5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x58C5 21744 bytes
SHA-256: b011e1808b97a09e22ef4cb72f21fbb8befc82b58c5a2eed687c37a9c5e0a994
font_01_sfnt_off000097cd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x97CD 5820 bytes
SHA-256: c7ab290d7675e1a55eb3daf76b3e9e6d536488d4b5429a8b8a06f4397d7b1bf1
font_02_sfnt_off0000ab84.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAB84 10284 bytes
SHA-256: 673d7c38e41d9ca3256fac5056afa2f7da3ec8bf7c8533cfa8f3aae43d98a9fd