Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f4feeee4cc2e88e…

MALICIOUS

PDF

40.0 KB Created: 2020-10-27 19:40:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2020-12-26
MD5: 59e504d78ec8e0ccfa241934072cfe16 SHA-1: 220f0ba3a337db5eccd9e2a55a95e6cc24b8a375 SHA-256: 0f4feeee4cc2e88e2f7efb53faa8cb497c0ecc47efb45b8e56354205c94a34d5
134 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/123?keyword=student+exploration+collision+theory+gizmo+answers In PDF document text
    • https://cdn-cms.f-static.net/uploads/4369927/normal_5f8e82b96fcd5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374986/normal_5f8f767add141.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367916/normal_5f8a196b53300.pdfIn PDF document text
    • https://s3.amazonaws.com/fejififimaketo/theories_of_technological_innovation.pdfIn PDF document text
    • https://s3.amazonaws.com/gavexilatuvitaz/81861701700.pdfIn PDF document text
    • https://s3.amazonaws.com/henghuili-files2/18182299830.pdfIn PDF document text
    • https://s3.amazonaws.com/felasorarabipis/vikumofabotugelub.pdfIn PDF document text
    • https://s3.amazonaws.com/nademopor/ketixenanawofutaseve.pdfIn PDF document text
    • https://s3.amazonaws.com/leguvefu/fenelapuj.pdfIn PDF document text
    • https://s3.amazonaws.com/mipeboro/online_to_word_converter_ocr_hindi.pdfIn PDF document text
    • https://s3.amazonaws.com/matogapibelifiv/genetic_algorithm_download.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393752/normal_5f949d5e71f78.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389097/normal_5f94d1ef85cb0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385202/normal_5f9582bdb1f50.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379220/normal_5f94f8d934553.pdfIn PDF document text
    • http://www.ascendercorp.com/In extracted file (font_00_sfnt_off00004fb5.bin)
    • http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off00004fb5.bin)
    • http://www.daltonmaag.com/In extracted file (font_02_sfnt_off0000823e.bin)
    • https://uploads.strikinglycdn.com/files/069c788e-dab0-4abf-b625-91ca1a2d9ca7/precios_nissan_2019.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e54513e1-1603-49da-82c0-c8a4e14c0e8d/73499348316.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/62083cdf-0a90-4db4-9e93-331b2e10a8b0/55577332733.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38dd61ca-fed8-4c2c-86e3-bc4df0df86d4/regarder_greys_anatomy_en_streaming.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7f5ef5a2-c7f4-454f-926c-b4b4f69eba9f/nusetubederu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ac45d3ae-4f92-4caa-90fe-158285d58794/24111083971.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f633ce27-aa9b-4cab-b4c7-2c13635014c2/38218497532.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ea39d462-61f7-4fa9-8506-53f20c6864fc/81390261686.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3362df17-f187-4224-b3aa-5cb45cb6a1e7/11951568692.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off00004fb5.bin)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004fb5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4FB5 5784 bytes
SHA-256: 69c1b94f67a7b7d3f06edc203df69e0254e60cd16f6d0475af14ef1d0e1e65e1
font_01_sfnt_off00006347.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6347 9088 bytes
SHA-256: 09f29acfdd4d09ad254e317181abef0f07c1800d95eeaf8715feb0cf2d760266
font_02_sfnt_off0000823e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x823E 4324 bytes
SHA-256: 7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71