Malicious PDF — malware analysis report

Static analysis result for SHA-256 831bad6f93f274af…

MALICIOUS

PDF

228.6 KB Created: 2022-11-20 02:52:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2023-12-06
MD5: c1aa4acf31d37f821ad7c2c189dc0184 SHA-1: 16bb8706719e112841638d6dbb7ea5717340413b SHA-256: 831bad6f93f274af375735501b928c06740f42f45c2b52f8cbeda018072fb670
106 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.8054

Heuristics 5

  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://diamant-x.sk/UserFiles/file/gudemasejab.pdf In PDF document text
    • http://abmys.org/kcfinder/upload/files/62987159112.pdfIn PDF document text
    • http://nek.ua/wp-content/plugins/formcraft/file-upload/server/content/files/163029b1f78937---dabakolozosupazaxin.pdfIn PDF document text
    • https://vadiwolor.weebly.com/uploads/1/3/4/7/134737839/e25efb395ca12.pdfIn PDF document text
    • http://www.admion.cz/upload/files/bodew.pdfIn PDF document text
    • http://ep9.cz/kcfinder/upload/files/51800104378.pdfIn PDF document text
    • http://www.tamilsaga.com/ckfinder/userfiles/files/tivegunexabamis.pdfIn PDF document text
    • https://smartbrand.ro/mm/file/39801731581.pdfIn PDF document text
    • https://gilolubirej.weebly.com/uploads/1/3/4/3/134309297/keviko.pdfIn PDF document text
    • http://zoltysnieg.pl/pliki_wyswig/files/93919154657.pdfIn PDF document text
    • https://swotin.com/wp-content/plugins/formcraft/file-upload/server/content/files/1633484eaa1cd7---6278360605.pdfIn PDF document text
    • http://keletunderground.hu/images/uploaded_pics/file/puxufodikizepi.pdfIn PDF document text
    • http://cocoal.com/uploads/file/konugirepurezajizisigoxuf.pdfIn PDF document text
    • https://wemoronekiwomek.weebly.com/uploads/1/4/2/0/142024556/9232284.pdfIn PDF document text
    • https://jemeleromonojo.weebly.com/uploads/1/3/4/0/134041090/1309403.pdfIn PDF document text
    • https://www.profiexpo.ru/js/kcfinder/upload/files/dipugolar.pdfIn PDF document text
    • http://msci.com.ng/wp-content/plugins/formcraft/file-upload/server/content/files/16321dffb87820---56078644174.pdfIn PDF document text
    • https://digalerusu.weebly.com/uploads/1/4/2/6/142654758/xuposuro_pepal_fulobosebitine_melalawisezekul.pdfIn PDF document text
    • https://dondepodemosir.com/userfiles/file/konazeroxivovatenotinato.pdfIn PDF document text
    • https://valolasezeg.weebly.com/uploads/1/4/2/4/142432507/kesemisukedorukam.pdfIn PDF document text
    • http://sciencevier.com/wp-content/plugins/formcraft/file-upload/server/content/files/1622b125175a4e---79326058506.pdfIn PDF document text
    • https://hoclichsu.online/public/uploads/files/27364996845.pdfIn PDF document text
    • https://scmsgroup.org/ckfinder/userfiles/files/78982621725.pdfIn PDF document text
    • http://netart.hu/userfiles/file/bugoziset.pdfIn PDF document text
    • http://kirpichi.su/kcfinder/upload/files/22934643835.pdfIn PDF document text
    • http://imi.vc/upload/files/dozosibuwasaxepezawalik.pdfIn PDF document text
    • https://bogatawokajo.weebly.com/uploads/1/3/4/9/134900502/416c3b190154bd.pdfIn PDF document text
    • https://smartcrm.cloud/upload/files/83378782067.pdfIn PDF document text
    • http://4998horo.gmmwireless.com/contents/files/40330181926.pdfIn PDF document text
    • http://foto-recepty.sk/images/fotky/tesekinisuzupagurejakemuf.pdfIn PDF document text
    • http://hosungtour.net/FileData/ckfinder/files/20220611_E88465649518214E.pdfIn PDF document text
    • http://belcanto-evenements.com/media/files/jalemixibimojufesufeb.pdfIn PDF document text
    • https://kiemtoandongnghi.com/public/plugins/ckfinder/userfiles/files/36768474058.pdfIn PDF document text
    • http://zatuchlina.cz/upload/file/zezomuvifenojo.pdfIn PDF document text
    • http://nicenpos.com/userData/board/file/dufivusosesi.pdfIn PDF document text
    • https://poxesaxe.weebly.com/uploads/1/3/0/7/130738711/xebapijasedadixatu.pdfIn PDF document text
    • https://foxuwulugoz.weebly.com/uploads/1/4/2/1/142127917/4094648.pdfIn PDF document text
    • http://canavesiobruno-architetti.it/userfiles/files/87241534829.pdfIn PDF document text
    • https://music-group-store.com/upload/files/47002185740.pdfIn PDF document text
    • http://www.sfainternational.pk/assets/ckeditor/kcfinder/upload/files/falidesowadipojo.pdfIn PDF document text
    • http://eelruxe.com/c3?utm_term=how+to+make+fire+message+in+messengerPDF link annotation
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off00033f1c.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off00033f1c.bin)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00033f1c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x33F1C 16596 bytes
SHA-256: 9dbfdb9d38ad84ac9c1a8096f645c20169bde32dbfa3889ceca857ebf61e9274
font_01_sfnt_off00036a45.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x36A45 10680 bytes
SHA-256: 5657a03f92238cc34ca6a64e93bbb8b38b7a904ce161f852cb63557dc4efcea9