Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e8e57f5045d7e0b…

MALICIOUS

PDF

71.8 KB Created: 2021-02-12 20:52:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-10
MD5: e9bc9d9c9f04aa56b22f6a8d3241194d SHA-1: 84a7cf737ed4ce0b027a38fe8d3e969349e30144 SHA-256: 7e8e57f5045d7e0b9b80501d3364fde9247936a288ed6334eb0876a7dedf07ee
126 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=kodi+17.4+apk+free+download PDF link annotation
    • https://fosovumukudire.weebly.com/uploads/1/3/4/2/134235423/d265aaf.pdfIn PDF document text
    • https://xarudaxukisa.weebly.com/uploads/1/3/4/0/134018653/676892a1.pdfIn PDF document text
    • https://cdn.sqhk.co/devepogisog/fZggfbm/9999725639.pdfIn PDF document text
    • https://cdn.sqhk.co/vodadavubex/e6MjfeY/clock_face_template_png.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380219/normal_601198ecbd3e2.pdfIn PDF document text
    • https://cdn.sqhk.co/bozadukopufu/Ujft1Gg/the_farm_sassy_princess_fishing_rod.pdfIn PDF document text
    • https://dasufurejer.weebly.com/uploads/1/3/0/9/130969026/wukuvepip.pdfIn PDF document text
    • https://cdn.sqhk.co/sononipo/BFARjjU/kavopuvumus.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4381344/normal_60209dc31904b.pdfIn PDF document text
    • https://cdn.sqhk.co/suxujaba/JihXhgi/phonto_text_on_photo_apk_download.pdfIn PDF document text
    • http://generalmassage.online/29723554631khplx.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4493553/normal_5fe316bf14aa3.pdfIn PDF document text
    • http://ultra0.space/repevobosaluxaxuj4dwbb.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4374532/normal_60078b94dcdad.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4446496/normal_601b61b25cd6c.pdfIn PDF document text
    • https://wafilanukeg.weebly.com/uploads/1/3/5/3/135309269/tafigixa_weperorel_poref.pdfIn PDF document text
    • https://dupazenulejafu.weebly.com/uploads/1/3/4/3/134331878/wuxuxigipawizubog.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc14.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC14 5236 bytes
SHA-256: a799e9ec6118d5ae495eab5e4090a2a41ebac086a3f132dd1690b7b9085083ef
font_01_sfnt_off0000ee22.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE22 10448 bytes
SHA-256: 85133577fd37ecaeb0a70aa4080500c776db00f9a7b1a64a189c1cb7f52b1ff6