Malicious PDF — malware analysis report

Static analysis result for SHA-256 c69fa67d874afb5e…

MALICIOUS

PDF

77.9 KB Created: 2020-11-16 20:24:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-31
MD5: d48aee25c44c2b7d00f2e885549e6523 SHA-1: 7d2961d9b259200c57bc692acfed893a29084b32 SHA-256: c69fa67d874afb5e65a0aeb41751fe8517f822cf40d38adff94937abcd423289
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The ML classifier also flagged this PDF with a high score, and ClamAV detected it as Pdf.Phishing.Trojan. The document body, though heavily obfuscated, contains text related to 'Trb 2020 call for papers', suggesting a phishing lure. No scripts were extracted, but the presence of malicious URLs indicates an attempt to redirect the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/123?utm_term=trb+2020+call+for+papers In PDF document text
    • https://cdn-cms.f-static.net/uploads/4445735/normal_5fa2074bbdf2c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4471109/normal_5fa40709d7728.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/aebe5e1d-36c0-4625-8d65-f31137add68b/city_politics_9th_edition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c77ad018-0e18-42ea-822f-39a1e2cfca5a/99410047981.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/09dd6d55-ff99-4ab0-bb03-f7de88024c7f/13037416207.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89343ddf-9885-4ab6-8278-816c2b69e5b2/bibiliya_yera_mu_kirundi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/603a036c-8e44-4625-8c06-1db3b7c35f80/saroluwusofumetelidenarul.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0bd1ec0a-bd99-42a4-9a1a-573a42f1648c/ya_no_soy_esclavo_del_temor_twice_letra.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b9749671-97d2-4a81-91c1-5ffcb7573cf9/fazapagodexoli.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bfb74281-175e-4933-99eb-ffabd58085d4/seteledulegopefalegu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bb839122-3197-4c5e-bc7c-1ec9fd58b944/happy_pet_story_hack.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4426d950-83a2-4156-8671-cbd4f41291c4/libro_administracion_de_sueldos_y_salarios_agustin_reyes_ponce.pdfIn PDF document text
    • https://s3.amazonaws.com/kavitokolezub/pathology_of_cardiovascular_disease.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/30ee36dc-2bc2-40ee-bba5-1d423dda5977/pelawibalofepo.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000def3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDEF3 5372 bytes
SHA-256: 2d2f2691d5d18bd508f3c2c572db5afe4d59d6d651dcc25935a231353776b32f
font_01_sfnt_off0000f145.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF145 10692 bytes
SHA-256: efac45a4f3c1ebcd4a100472b16a9a2fd28079e24121e5fbcbf1886fe5192d14
font_02_sfnt_off000115ed.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x115ED 16060 bytes
SHA-256: 5b0d2701ab39d2f69c66d7d16c60d8db0b323aa0832947137e757b5401d27330