Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ee940e680fd6245…

MALICIOUS

PDF

110.2 KB Created: 2021-03-22 06:22:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0d41989566e4c72d65f19f07dab51452 SHA-1: 929164e20e47c12c568d9b3998d20dd59dce31a5 SHA-256: 7ee940e680fd6245a17fd7072b4c32498de17be87d8168978c3e9e23936f479e
118 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • ClamAV scan did not complete info CLAMAV_SCAN_INCOMPLETE
    ClamAV scan on this file did not complete (ClamAV error (exit 2)); the verdict reflects only static heuristics. The result is not cached so a later submission will retry the scan.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=single+parent+leave+in+the+philippines
    • http://finipupote.mywebcommunity.org/vogewinasudegu.pdf
    • http://operationhomeplate.com/how_do_i_program_my_att_uverse_remote_to_my_insignia_tvdx6i5.pdf
    • http://sizinepizot.scienceontheweb.net/vovibuzanazebedepuli.pdf
    • https://velazidolis.weebly.com/uploads/1/3/0/9/130969689/pizula.pdf
    • http://securitycheckingbrowservkcom.xyz/twitter_mission_statement_analysistda3g.pdf
    • https://wewodagib.weebly.com/uploads/1/3/4/2/134266566/8872a71cd.pdf
    • https://lipuxavevafip.weebly.com/uploads/1/3/1/3/131398459/3540c0794b00111.pdf
    • http://podarokinsta.site/tusivuzuzawopilanomufifz5pz.pdf
    • http://bcpzonasegura10beta-viabcp.com/social_problems_in_the_communitywsbtz.pdf
    • https://liramuxusere.weebly.com/uploads/1/3/4/5/134577046/3963329.pdf
    • http://patajafurep.mywebcommunity.org/zedumov.pdf
    • http://site-shop.xyz/90394255387iyonj.pdf
    • http://esagafow.fun/pubg_not_ing_from_play_storexo94t.pdf
    • http://graatorama.fun/nys_lcsw_exam_study_guidebmc1a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nijosinizo/96985156668.pdf
    • https://s3.amazonaws.com/lolaritemukole/simplifying_negative_exponents_with_variables_worksheets.pdf
    • https://s3.amazonaws.com/vibuvomomuv/product_backlog_refinement_scrum_guide.pdf
    • https://7133fc40-0b9c-4701-b953-e7fafc934b44.filesusr.com/ugd/70a38d_9b681cf4a4fc4edb87fe2488b7b77cb1.pdf?index=true
    • https://s3.amazonaws.com/baposivarabuj/bounce_rate_website_template.pdf
    • https://3df06c22-1e8a-4082-8cc2-a0fdc0609706.filesusr.com/ugd/d86e81_6b08a9c2323b484b80720b9c0c00afab.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00016ca8.bin
ca23fc16660310b60246e1a3dd83fe266e23dcd58741ae2c7053146c8aa4d923
pdf-font-stream PDF embedded font (sfnt) at offset 0x16CA8 5244 bytes