Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb57af1d5e05c493…

MALICIOUS

PDF

86.5 KB Created: 2021-05-30 00:21:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 3179c49fcd5ee56eb1581b31648638ee SHA-1: 52695955ec8600176bf6e2032bb5658a7f7896f8 SHA-256: bb57af1d5e05c493d26010c2b83d5aab5e12388fb893a463f5d9ce1684ba1f82
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by multiple heuristics, including a critical alert for a PDF redirector link to a known malicious URL. The ML classifier also flagged it with high confidence. While no scripts were extracted, the presence of a malicious redirector URL strongly suggests an attempt to lure the user to a harmful site, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/123?utm_term=fallout+d%2526+d+sheet In PDF document text
    • https://static.s123-cdn-static.com/uploads/4403537/normal_5ff8bb49a75ac.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4385214/normal_5fcf280da16e6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4381294/normal_6048cca5a994a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4502248/normal_6012d0b9c82dd.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4380867/normal_5ff62323d96be.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450249/normal_60676adb47d78.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380700/normal_601295295a54f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489844/normal_605d95ab53f26.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413975/normal_6021e97465c63.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4407299/normal_5fee1c6664d61.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391909/normal_603795903a1ba.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4392661/normal_5fed820b6a35a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4451350/normal_5ffb05cbe7eff.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4392191/normal_60064eab42a82.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393019/normal_6048653fd4d7f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404121/normal_603c520f9e934.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383703/normal_604a8fec14c99.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4414695/normal_6030e86610b47.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4410216/normal_5feb9bcf5ef93.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420610/normal_603e5d3d431e2.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/46821600-2590-4fad-b8fb-98c793aa760e/zojirushi_bb_cec20.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/06bc2cbb-2010-41ec-895c-cec0c3e8d7ce/miracle_latest_crack_without_box.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/57afdeef-bf54-45ac-93f2-f7ba4c48379c/wederomowiwi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9f163170-0e29-44c4-b6e3-60ecde5191df/how_to_set_up_my_brother_wireless_printer_to_my_ipad.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a4d8215-a4b9-454e-b9ae-45ebe6254449/stealth_cam_fusion_troubleshooting.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010665.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10665 3080 bytes
SHA-256: 3b6c3edccbbdf68622c80e44ac099bd4bffa00507f4f1bc839f0bdbf087aa810
font_01_sfnt_off0001116f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1116F 4500 bytes
SHA-256: 90bd621d60b0cbec16b106280253b248b046d1cd0f041f47dd805ec0e7131670
font_02_sfnt_off000120cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x120CF 14908 bytes
SHA-256: 7d02aae1959aeed0fe562715f6dd02dd020acd08248aeddc82867db1c79f656b