Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6de937ea8b8b36c…

MALICIOUS

PDF

94.8 KB Created: 2020-12-14 23:01:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 2818cff2a3e9e17f16899393a69b7db2 SHA-1: d908d90111612022260c98976d8bbe1ea3542b25 SHA-256: f6de937ea8b8b36c861991567e8f60f5a207cd5844c1e60615abb268d91c6f91
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. It uses a callback-phone (TOAD) lure. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffmen.ru/strik?utm_term=it%2527s+always+sunny+in+moscow In PDF document text
    • https://cdn-cms.f-static.net/uploads/4459164/normal_5fad5f70aec3a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417140/normal_5fa7da1330c05.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372980/normal_5f88fd66a3623.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404108/normal_5f9aa1e919558.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450426/normal_5fa4216b0f490.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd18d15e198d0a38642686/1606228178750/stephen_king_ur.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc5cd3c27a199023ad6e49f/t/5fc7ebef8fd22f2eb9ee141e/1606937584446/hover_1_allstar_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7778d3fe-2608-41c4-9ecc-8edeef53488c/tulavetibefo.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc51130ea4a794d565ff698/t/5fd16368880fa23343c6aca3/1607557993534/amazon_prime_golf_rangefinder.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc172dc1452f90b7fe9340e/t/5fcbd8dd1415195da0914093/1607194849704/prepper_website_australia.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc5141627a199023ad05ad4/t/5fce11877ae85b53b2b91495/1607340423957/37079457338.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0d4086b97992eb55bb7f9/t/5fc1f748645712565482525e/1606547272815/75683662916.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/97e9bcaf-3873-4a6d-8d3a-25d30e3a3ad7/39199487399.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000113bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x113BF 2964 bytes
SHA-256: f4bf3d0520e8ad85c655520e0264792aa2c98d1952f871b332de490ae8e99eb1
font_01_sfnt_off00011e49.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11E49 5016 bytes
SHA-256: 08375929b14dfba01e762d9f4421890e30f5bed3d99e601f40efe7a5d656a6b0
font_02_sfnt_off00012f67.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12F67 11196 bytes
SHA-256: ae1af2ef354dbf79931dd49a0f33fea68e6eb2b39b95393254a5cc2df55e9102
font_03_sfnt_off000155da.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x155DA 16416 bytes
SHA-256: 1b19f5b9ae2aeff7929e120295d9aee049321614abc14b3ca723126b23f9dd5b