Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ede3a060f8c05e9…

MALICIOUS

PDF

45.0 KB Authoring application: QPDF First seen: 2021-02-20
MD5: c78b283bcddf633306b2396341f7e345 SHA-1: aa22c932c380a584deecb39d4253c048e72c6349 SHA-256: 5ede3a060f8c05e9865b4edea0e96d73f3a420541c802874228c41a9809807f6
172 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Pdf.Dropper.Agent-7819752-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7819752-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://missionarytoargentina.com/uploads/1/3/0/7/130740521/nabesewotud.pdf In PDF document text
    • http://beatsbytheharv.com/uploads/1/3/0/6/130620622/lidur_bozakovezekol.pdfIn PDF document text
    • http://worldofcoffee-dublin.com/uploads/1/3/0/3/130323693/pugijuginodaguver.pdfIn PDF document text
    • http://fovozovoge.alltoptoxx.ru/uploads/2020/01/29/a827b9c.pdfIn PDF document text
    • http://chrisbarnwell.com/uploads/1/3/0/7/130738894/8854592.pdfIn PDF document text
    • http://miamipwcparts.com/uploads/1/3/0/7/130775752/lapidobefik_zuxumogip_fogojuta_teberebejodi.pdfIn PDF document text
    • http://10xoceansolutions.com/uploads/1/3/0/5/130588221/130588221.html#jigsaw+blade+guide+armIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12F8 8804 bytes
SHA-256: f6fd4b7a2dd2cd727918f0d6f37af7ded59129ec4551835daedbd3024ac1caf1