Malicious PDF — malware analysis report

Static analysis result for SHA-256 081e3dca5552f5ac…

MALICIOUS

PDF

44.9 KB Created: 2020-10-17 22:10:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-15
MD5: b7d4dfd3b3b38c430efe3bf46ec43bd9 SHA-1: 622cfedab9e2557dca621bd9932ddae8a9e07b04 SHA-256: 081e3dca5552f5ac5a1528a3eff70d5391efdd89cfd159672245b3922686d96e
184 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/123?keyword=2020+honda+fit+maintenance+manual In PDF document text
    • https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/zebetuwi.pdfIn PDF document text
    • https://nudopimiga.weebly.com/uploads/1/3/1/0/131070212/radodasiv.pdfIn PDF document text
    • https://nudopimiga.weebly.com/uploads/1/3/1/0/131070212/vikaxobotomapi.pdfIn PDF document text
    • https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/filosom-lusiwikafese-jerupuxorukoti-novubolifunuw.pdfIn PDF document text
    • https://meboguvogo.weebly.com/uploads/1/3/1/4/131437667/lisibojuk.pdfIn PDF document text
    • https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/nagogivewufila.pdfIn PDF document text
    • https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/gowexewovape.pdfIn PDF document text
    • https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/dukuz.pdfIn PDF document text
    • https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/kijejelakenat-gewigopaparax-luledod.pdfIn PDF document text
    • https://gewosawoma.weebly.com/uploads/1/3/0/7/130739201/b9cee03b2.pdfIn PDF document text
    • https://bebamewikirebu.weebly.com/uploads/1/3/0/8/130874540/bijerima.pdfIn PDF document text
    • https://wavuvavezexa.weebly.com/uploads/1/3/0/7/130775629/4831658.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/15808499-75c2-451a-a87b-adbd904feb39/46122744141.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d3f4385-f8e4-4172-8991-54395f1b21ef/78806736015.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d6ff105-9e1d-4279-a655-cc36f3e3a4c7/valatokexutirufitexo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/274cc579-6068-4063-9524-673e941101bb/zinokexobuwuriko.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2b527817-619d-4a91-9fe8-9a46b39ae8de/24865898935.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6679f232-85ab-4a47-934d-d0c21403fd61/desutekewexo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d9982d9-dee9-4115-89f2-52412a83100c/lawabiwevaninuludo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f718a84-95b8-4746-bd61-20371c323c97/32510721617.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8de37a3d-da0d-49cc-b456-d379f16b596d/loxazebumisegotedaw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9498450c-063c-493d-ba2d-66d32a3b2537/zuxuxavi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/287c8648-1b38-425a-a5ac-e7c30223cecb/744245509.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bd2eb530-48f8-49f7-a0e7-83c6df4bb9a6/vilavabovepi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e935f6dd-3981-4645-834b-30f032bacb21/21749391436.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d0f1f19f-2004-4442-ad85-053118610472/pekawewewonalefuvi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000724e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x724E 5168 bytes
SHA-256: 5eeb31d5622f1f31a3cf5cac5c4c9fb64769d426c92278a7577b8044f8a99af1
font_01_sfnt_off000083a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x83A8 9968 bytes
SHA-256: d71e9ad28f5c0774308fedd06bce8c547d8acca5ff183fb680cca224555733bb