Malicious PDF — malware analysis report

Static analysis result for SHA-256 8a104ae7eb118883…

MALICIOUS

PDF

83.5 KB Created: 2021-04-20 17:24:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: 3ee6511e7a8f6383e50b16292833bad3 SHA-1: 02e97943c9f7bc94a32b0f2ed0cb58ca19ad032c SHA-256: 8a104ae7eb118883f96fab673347f0762e8eb74dfe72c9e884fdd6d420f2c980
156 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/strik?utm_term=logitech+mm50+remote+control+battery PDF link annotation
    • http://sdek-24.cc/lolosizakavomebugefakezeua.pdfIn PDF document text
    • http://naturka.space/14267272104djpn8.pdfIn PDF document text
    • http://skout.tech/15761823441roq5q.pdfIn PDF document text
    • https://mivifasev.weebly.com/uploads/1/3/1/4/131483453/ripaguzeresojuf.pdfIn PDF document text
    • http://thiswaytovogue.com/45005967289ubz1a.pdfIn PDF document text
    • http://atomyimperial.ru/22625639203lbb8o.pdfIn PDF document text
    • http://tublitalia.fun/67774707720euafg.pdfIn PDF document text
    • https://lutasuboli.weebly.com/uploads/1/3/2/7/132740498/bojazalid.pdfIn PDF document text
    • http://oneshops.space/land_guideline_value_in_velacherydovcq.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jiwotarotavuz/calendario_milan_2018_19.pdfIn PDF document text
    • https://e37fb4d6-fac4-4cb1-96d9-cce2dae532e5.filesusr.com/ugd/ed2751_bdb9a3d0691741249f770e5b9af6041b.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/rabewiruzitewa/68760491889.pdfIn PDF document text
    • https://s3.amazonaws.com/dopugaxelelema/fisher_and_paykel_dryer_spare_parts_brisbane.pdfIn PDF document text
    • https://s3.amazonaws.com/wonumafubij/roku_ultra_remote_1_and_2_buttons.pdfIn PDF document text
    • https://26c1613e-5d28-4fa3-89cb-3d2c9ab59faf.filesusr.com/ugd/fe83c3_d8c4690c90e649b99f0b4067b811d94d.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/mozedijiz/13892839019.pdfIn PDF document text
    • https://s3.amazonaws.com/fifuto/nixon_51-30_chrono_leather.pdfIn PDF document text
    • https://41c240d9-b4af-4f88-8fa4-2a41cce3a287.filesusr.com/ugd/01bc73_b7a6128704614b2889714056532ae4c9.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/gavexilatuvitaz/cbse_maths_textbook_for_class_4.pdfIn PDF document text
    • https://s3.amazonaws.com/novifamigot/how_to_increase_your_vertical_jump_quickly.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0a4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF0A4 5484 bytes
SHA-256: 27476eef49b2c147a6a3a6fc8ebff33956cd51b8a24b4a8bb0be21a8845bc041
font_01_sfnt_off00010335.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10335 11468 bytes
SHA-256: 07655f2dd84206fd76eaad9b08e8b9194f7f1ac007a3611fe6764efbc4675072
font_02_sfnt_off00012a80.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12A80 16376 bytes
SHA-256: 069f5cdcb972b33999f3dc18a3e5b847fc2aa024b7c5b45b4734cedf253a8e5c