Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b6f49cd96055f89…

MALICIOUS

PDF

103.3 KB Created: 2022-12-12 13:15:49 +00:00 Authoring application: halsnelw (via mPDF 8.1.2) First seen: 2023-12-10
MD5: 217214991f021565a0e78b63c2a6844c SHA-1: e6228da7c2190350f00274bfd10d76d86ab0969b SHA-256: 4b6f49cd96055f89b7ec278e93daa6d83d9be777c9f6426734fde5c0526d45f7
264 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0031

Heuristics 8

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cracked-software lure uses shortlink/download gateway critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
    PDF visible text advertises a crack, serial number, archive, or pirated-software download and pairs it with a shortlink or encoded download gateway. This is a high-confidence social-engineering carrier for unwanted software or droppers; the PDF itself is not a parser exploit.
  • Cracked-software lure uses download-gateway redirectors high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
    PDF contains multiple cracked-software/keygen/serial-key lure links together with long encoded download-gateway URLs or known crack-download redirector hosts. This is stronger than generic piracy vocabulary: the document is an SEO lure that funnels users through redirect/download infrastructure commonly used for adware, unwanted software, or droppers.
  • PDF links to a cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
    PDF's embedded link hides a pirated-software title as a base64 blob inside the URL path/query (and/or carries the ``download|`` doorway-template marker), rather than in visible text. This is a TCPDF-generated SEO doorway that ranks for software-piracy searches and funnels users to fake 'crack/keygen' download pages distributing adware, potentially-unwanted programs, or droppers. The base64 encoding is deliberate obfuscation to evade plaintext lure rules; the PDF itself carries no parser exploit — the risk is the linked crack-download destination.
  • PDF link farm advertises cracked/pirated software medium PDF_CRACKED_SOFTWARE_LURE
    PDF contains many clickable links whose targets use cracked-software, keygen, serial-key, or warez vocabulary. These are SEO-spam lure documents that rank for software-piracy searches and route users to fake 'crack' download pages distributing potentially-unwanted programs, adware, or droppers. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://signforcover.com/conclusion/nosepiece/dactylitis/jankel/ZG93bmxvYWR8dDQ1TTNaaWVueDhNVFkzTURnek5ETXdPWHg4TWpVNU1IeDhLRTBwSUZkdmNtUndjbVZ6Y3lCYldFMU1VbEJESUZZeUlGQkVSbDA/parikia/QUJDIFJvc3RlcgQUJ/refraction== PDF link annotation
    • https://www.bullardphotos.org/wp-content/uploads/2022/12/Portable-XP-Theme-Source-Patcher.pdfIn PDF document text
    • https://amnar.ro/wp-content/uploads/2022/12/TIFF-To-AVI-Converter-Software.pdfIn PDF document text
    • https://tidmodell.no/wp-content/uploads/2022/12/uranragu.pdfIn PDF document text
    • http://thehealthyzoom.com/wp-content/uploads/2022/12/Qi-039rat-Quran-Reciter.pdfIn PDF document text
    • https://indalienergy.com/wp-content/uploads/2022/12/lanarne.pdfIn PDF document text
    • https://explorerea.com/wp-content/uploads/2022/12/IZotope_Ozone_Standard_Free_Download.pdfIn PDF document text
    • https://livetechspot.com/wp-content/uploads/2022/12/sigphi.pdfIn PDF document text
    • https://multipanelwallart.com/wp-content/uploads/2022/12/nanykhr.pdfIn PDF document text
    • https://astrofiz.ro/wp-content/uploads/2022/12/qpress.pdfIn PDF document text
    • https://www.fourwheels.it/wp-content/uploads/2022/12/hastirin.pdfIn PDF document text
    • http://signforcover.com/conclusion/nosepiece/dactylitis/jankel/zg93bmxvywr8ddq1ttnaawvuedhnvfkzturnek5etxdpwhg4twpvnu1iedhlrtbwsuzkdmntundjbvz6y3lcyldfmu1vbejesuzzeulgqkvsbda/parikia/qujdifjvc3rlcgquj/refraction==In PDF document text
    • http://dejavu.sourceforge.netFontsIn extracted file (font_03_sfnt_off000164d9.bin)
    • https://techplanet.today/post/hd-online-player-titanic-movie-download-in-hindi-hd-720691-verifiedIn PDF document text
    • https://techplanet.today/post/street-fighter-x-tekken-psp-isoIn PDF document text
    • https://techplanet.today/post/trainz-simulator-2010-engineers-edition-skidrow-top-crackIn PDF document text
    • https://reallygoodemails.com/pilawconbiIn PDF document text
    • https://new.c.mi.com/my/post/635525/CRACK_Native_Instruments_Guitar_Rig_5_Pro_V522_UNLIn PDF document text
    • https://techplanet.today/post/uncharted-4-a-thiefs-end-redeem-code-generatorIn PDF document text
    • https://tealfeed.com/torrent-download-updated-powershape-2014-download-ossc9In PDF document text
    • https://techplanet.today/post/adobe-media-encoder-cc-2015-900222-64-bit-top-crack-keygenIn PDF document text
    • https://new.c.mi.com/my/post/635525/crack_native_instruments_guitar_rig_5_pro_v522_unlIn PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_017_off0000f10d.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_017_off0000f10d.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseDejaVuIn extracted file (font_03_sfnt_off000164d9.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_017_off0000f10d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF10D 19780 bytes
SHA-256: 4fa1e1f62893db1504b694ba157ca733dbc9a64fe6775bec7c5c9e8d41f3a745
font_00_sfnt_off00004f8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4F8A 60428 bytes
SHA-256: 05473cfaffcf8637144420db76c1763c6ee018df57c3d2f5a1a80787bc6d8cee
font_02_sfnt_off000130d9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x130D9 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8
font_03_sfnt_off000164d9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x164D9 26892 bytes
SHA-256: 440ba7b1b0fb2eb971275b07a98648fad327a18a6221b47420b3d824bf3a407a