Malicious PDF — malware analysis report

Static analysis result for SHA-256 f16a8b3598cc158c…

MALICIOUS

PDF

95.4 KB Created: 2021-04-28 01:41:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 62f974a3b7b593215351b8165744084d SHA-1: df571b3768f8a6c9febcc9d0bb1f4314a849b54b SHA-256: f16a8b3598cc158cfde1421bdf587debd69b3c367ff62b20d492a6997548704b
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=fl+studio+12+old+version+free+download In PDF document text
    • https://cdn.sqhk.co/negolura/Aij95gh/sheltered_in_the_arms_of_god_ukulele_chords.pdfIn PDF document text
    • https://cdn.sqhk.co/wepenujofow/iihGHjj/38855126773.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403952/normal_6055a2f90fc99.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408881/normal_6043e077b8e8d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495264/normal_603008b1a78e0.pdfIn PDF document text
    • https://cdn.sqhk.co/bisidilit/hhfgjaH/pac_man_fever_song_music_video.pdfIn PDF document text
    • https://cdn.sqhk.co/fupupusamun/OBWidqQ/mode_sans_smp_mcpedl.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4497348/normal_603fbefba6967.pdfIn PDF document text
    • http://xibesofene.22web.org/motorola_ms350r_35-mile_talkabout.pdfIn PDF document text
    • https://cdn.sqhk.co/tokititagiwe/TFP62SM/91299308152.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4481286/normal_600a5961c9ba0.pdfIn PDF document text
    • http://podixugojunudir.22web.org/ametropias_2020.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470019/normal_5ffb43ac28775.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4385021/normal_5fe01e8a7c8dc.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/figidireki/17194630294.pdfIn PDF document text
    • https://s3.amazonaws.com/genedonapubefe/romikup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d41dcf6d-c81e-4cfe-b0c5-9501d341cf11/teledyne_laars_endurance_boiler_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/wizitifowubux/niliwiralezimomibiluvu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a39acc62-5061-48e9-a6df-d218b1f53955/89343761041.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/075c6aed-ebf3-4c2f-8487-3e90224f7235/why_we_sing_by_kirk_franklin_lyrics.pdfIn PDF document text
    • https://s3.amazonaws.com/ligole/charlie_movie_in_tamil_dubbed_free.pdfIn PDF document text
    • https://s3.amazonaws.com/fewifuwu/bully_english_3_answers_xbox_360.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/09b1cd39-6f11-47b5-8a8f-3dbd3b53c587/how_to_fix_error_51330_on_wii.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f223a128-7bc3-43fb-8a17-05f661390b62/civil_engineering_reference_manual_for_the_pe_exam_13th_edition.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001295d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1295D 5072 bytes
SHA-256: 72311937374182fa9ff6abb97e800861bb70cd11a2790807f3fc6f59dca97529
font_01_sfnt_off00013abe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13ABE 11544 bytes
SHA-256: 99eb67f548b316f31ea5f7f1ca69e364e21a82e0c62f4277fc43f177b8011d48
font_02_sfnt_off00016243.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16243 4324 bytes
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176