Malicious PDF — malware analysis report

Static analysis result for SHA-256 3310c021a8331325…

MALICIOUS

PDF

70.7 KB Created: 2021-02-11 20:19:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-04-25
MD5: 735e0a906eca8951544e8fb05f067bb3 SHA-1: ad1273e6e7f46e476ec9cb4a3c634fad032488c4 SHA-256: 3310c021a8331325876e17892ba7b3d45e2b7e4ffa27a6070695085d12b92c55
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/wix?keyword=egg+inc+mod+apk+happymod PDF link annotation
    • https://cdn.sqhk.co/zunesunatiri/gjiehjE/army_prt_standards_chart.pdfIn PDF document text
    • https://cdn.sqhk.co/fasotaluvose/hMVlARR/29648492630.pdfIn PDF document text
    • https://cdn.sqhk.co/divojimo/CqhBjhi/34831806560.pdfIn PDF document text
    • https://cdn.sqhk.co/zunezafi/jkdjfjj/pilabekovopugakagewudova.pdfIn PDF document text
    • https://cdn.sqhk.co/vumulevezuf/ibhgrhU/music_player_bass_booster_free_download.pdfIn PDF document text
    • https://cdn.sqhk.co/lerapuraroke/hjja9Mr/best_game_screen_recorder_for_pc_free_download.pdfIn PDF document text
    • http://gayerkan.com/airtel_dish_tv_cartoon_network_channel_numberuagy9.pdfIn PDF document text
    • https://cdn.sqhk.co/xinovupu/jjMibio/gikagaka.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/petuzutemixuvod/aashiq_banaya_aapne_song_2005_tinyjuke.pdfIn PDF document text
    • http://faxumev.epizy.com/kendo_ui_grid_react_template.pdfIn PDF document text
    • https://s3.amazonaws.com/peveziwoguxuzam/kotizubofazozatatu.pdfIn PDF document text
    • http://pixunarev.epizy.com/2771625598.pdfIn PDF document text
    • https://s3.amazonaws.com/dozuga/regulatory_change_impact_assessment_template.pdfIn PDF document text
    • https://s3.amazonaws.com/dudurat/45352421586.pdfIn PDF document text
    • https://s3.amazonaws.com/suzujewa/payback_3_apk_hack.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d4d5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD4D5 5304 bytes
SHA-256: 5984a6cc84a550a0905ff8d92660f5039025e2db9ba4e746307acc64422b321b
font_01_sfnt_off0000e6cf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE6CF 13140 bytes
SHA-256: 5fa90a17f8ec0281e7e32d0cf0c6674fac4ec0229ade9c319301f9da8178b4ae