Malicious PDF — malware analysis report

Static analysis result for SHA-256 036dc6df8d7cc420…

MALICIOUS

PDF

55.0 KB Created: 2020-11-07 00:02:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-01-10
MD5: 724ccd492ddad2b7bf86ed3f88aa1518 SHA-1: 9fa80475a3491e057ed1304388ac056a370bb037 SHA-256: 036dc6df8d7cc420b9c57312a07d554305ea390bab91194f345a501b944a19ea
96 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?keyword=schumacher+speed+charger+xc6+manual PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4384835/normal_5f8c9637158b1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4410985/normal_5f9cdec69df8d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369164/normal_5f9b8fec388ab.pdfIn PDF document text
    • https://toxekemugig.weebly.com/uploads/1/3/4/4/134484635/valepalif.pdfIn PDF document text
    • https://s3.amazonaws.com/lovetijif/dover_elementary_school_arkansas.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4376602/normal_5fa279d55c56a.pdfIn PDF document text
    • https://s3.amazonaws.com/bovenotojitowe/shadow_fight_2_cheats_android.pdfIn PDF document text
    • https://s3.amazonaws.com/dixaleko/xonokutovarixiniwazipuz.pdfIn PDF document text
    • https://rigafefabapamum.weebly.com/uploads/1/3/4/4/134486683/523502.pdfIn PDF document text
    • https://s3.amazonaws.com/tazibabebamep/osrs_slayer_masters_osrs.pdfIn PDF document text
    • https://s3.amazonaws.com/tajimipojimo/fujujuroxena.pdfIn PDF document text
    • https://fasuwilobavofe.weebly.com/uploads/1/3/4/4/134489762/zisuwonuzedafuzus.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367687/normal_5f874fa52cf34.pdfIn PDF document text
    • https://lunejuwibamir.weebly.com/uploads/1/3/4/5/134587588/nitoxuvililu.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_01_sfnt_off00009225.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_01_sfnt_off00009225.bin)
    • https://uploads.strikinglycdn.com/files/4a83d2dd-938f-44ea-a467-2404b20d31d9/50519056272.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_01_sfnt_off00009225.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000087dd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x87DD 2888 bytes
SHA-256: adf32003828e0940dd70a9ab198bdbf787bfce6d516b45b646911e816e1ab742
font_01_sfnt_off00009225.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9225 5812 bytes
SHA-256: 5bea3d797494fe3c6047cd5a6d60a725092b205e7554f8b3e8b5fcce9e225bff
font_02_sfnt_off0000a5c7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA5C7 11872 bytes
SHA-256: bf3cd428ffe0f95a5601ff48ac9f3757c2a41c6bb4d84dcf5c5d9f9156ad6a26