Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e235f7cebf3f0da…

MALICIOUS

PDF

73.1 KB Created: 2021-03-07 10:52:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-04
MD5: dea160fdcae39f6a968b2c211dde8842 SHA-1: 1b3d80faa903c1b3f3a62301e27bd49d3ddcf5fc SHA-256: 0e235f7cebf3f0da3f49de08ba6097961a6ecfe2ae5c1ea934d88eadd2f12664
76 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=after+anna+todd+pdf+italiano PDF link annotation
    • http://dkmz3.club/bare_knuckle_fighting_resultsulof2.pdfIn PDF document text
    • http://mishgen.com/nevusumonijamaduaf5n0.pdfIn PDF document text
    • http://lishop.site/jitosaxawvoocr.pdfIn PDF document text
    • http://inmyshtangen.xyz/sql_server_2017_enterprise_licensing_guidegzkka.pdfIn PDF document text
    • http://tafagejiveduda.22web.org/35667447548.pdfIn PDF document text
    • http://korirojasutito.22web.org/pefifetu.pdfIn PDF document text
    • http://lavka-karamel.ru/biguanides_davispdniy.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413987/normal_6028f8a442300.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4389804/normal_5fc70ea8945bd.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zerepuzuze/facetime_app_for_iphone_free.pdfIn PDF document text
    • https://2ac56fc1-f7ee-4366-9cb2-1681469c68ee.filesusr.com/ugd/b914b5_8226c1dbb6194e528481b67ffe212f90.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/bededuxotulapil/badri_movie_audio_songs_naa_songs.pdfIn PDF document text
    • https://cf336f9a-6a79-4542-9269-5b62d6eb69dd.filesusr.com/ugd/1daf83_2119c7d96b034ebda4bca7a8e482f499.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/mupukesunobaga/navy_dive_tables_rev_7.pdfIn PDF document text
    • https://b064d0e4-88d6-4b7e-8087-8ebf790fcba6.filesusr.com/ugd/ca32a8_5314c5834d86454794e908142a03228e.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/luworizesupox/72060409192.pdfIn PDF document text
    • http://xizabefozuk.rf.gd/baaghi_2_full_movie_song_video.pdfIn PDF document text
    • http://loxonugowutaj.rf.gd/libro_aprender_espaol.pdfIn PDF document text
    • http://nefotux.epizy.com/revozebi.pdfIn PDF document text
    • https://48bf584d-d56c-45cf-b4f3-c1c05dce5274.filesusr.com/ugd/3f4b99_146e4ccf3f6d470db004b4bca340d4ed.pdf?index=trueIn PDF document text
    • http://jojomuge.epizy.com/89522984893.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e419.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE419 4848 bytes
SHA-256: f98a41a3a13b10cef69591484ccfa6dcf78e4ce1c97424e50b3c2af74507a49e
font_01_sfnt_off0000f4a7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF4A7 10184 bytes
SHA-256: e4fa93e5c8d013e8c7bb83b96efcc7b656818e27773f09275d077b6f5126089b