Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d1747087aa68b87…

MALICIOUS

PDF

64.3 KB Created: 2020-11-03 02:20:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-02-23
MD5: a290ebd56f5a880cfd5c928d7898a8bb SHA-1: b6747e19e3b1411578f30eb9f3d9f4b357676968 SHA-256: 2d1747087aa68b87eaa02d8b11ce4020d69b12e184ebe6f25b6f208a0811f8bc
194 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/123?keyword=ipad+4th+generation+manual+pdf In PDF document text
    • https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/bidopinijixuni_zupap_zosedasaxenim.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.fontrix.comhttp://www.nhncorp.comIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/henghuili-files2/wordly_wise_3000_book_3_lesson_7.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/42593b81-a90b-4c2e-b10f-226d39b8b285/biochemistry_5th_edition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4229efd8-5d9c-4fdc-825f-e289d7202def/60621685765.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/08a1caa3-7350-4aea-b278-8f20492a46fa/93395892260.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0502/5385/6921/files/gktoday_month_wise.pdfIn PDF document text
    • https://s3.amazonaws.com/felasorarabipis/great_civilizations_of_ancient_africa.pdfIn PDF document text
    • https://s3.amazonaws.com/fojaxexino/57621270980.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7356ebf4-599b-4b48-9852-24dd5bca7d01/27655712.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0500/2349/7877/files/b_and_v_pronunciation_worksheets.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0486/1630/8896/files/thinking_putty_bulk.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008151.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8151 5684 bytes
SHA-256: e1a78a185f2e7b4a7faba422fb3995e0878a6e1f228b4a78e8a3df6a713d7f89
font_01_sfnt_off0000952b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x952B 5184 bytes
SHA-256: e31bc7fb62fa3a0e88c5bbf37dddcbc9037aa81d9e8bb43c6d963c033f774f2b
font_02_sfnt_off0000a69d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA69D 2180 bytes
SHA-256: 816a59b5fe19ab1517a17d73b9c00f49633eaa4c445426709c4efca152ba7d0e
font_03_sfnt_off0000affe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAFFE 14700 bytes
SHA-256: 4a1418e8105d450a685c70430f087417a42a42da1fabc18992d0ab153570b952
font_04_sfnt_off0000dc37.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC37 2104 bytes
SHA-256: bbd58a00ed2058e8974dcf5e54fc1fb25d15c76a27b94e571c38adfd9ab923fe
font_05_sfnt_off0000e51d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE51D 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3