Malicious PDF — malware analysis report

Static analysis result for SHA-256 975931168b753948…

MALICIOUS

PDF

78.4 KB Created: 2021-06-14 16:17:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0f6bdf9aa3a76cf9edbcc6d6f65f55f7 SHA-1: 6d539052f7bddb13c7ac05bef9a9a596ef2a37bd SHA-256: 975931168b753948abcaf31b358f6c11721acbf0733cbf5ba9cc31931debd4c4
164 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/pbw?utm_term=porn+games+free+iphone
    • https://cdn-cms.f-static.net/uploads/4444850/normal_60355f22d170f.pdf
    • https://cdn-cms.f-static.net/uploads/4484804/normal_605f33bb37f45.pdf
    • https://powudeli.weebly.com/uploads/1/3/4/7/134772307/07e5a8f060.pdf
    • https://cdn-cms.f-static.net/uploads/4482023/normal_60582941dab9f.pdf
    • https://nategenuniko.weebly.com/uploads/1/3/4/7/134749174/vudumoribupexo_kunazexa_wugomerila.pdf
    • https://fuwidomanajano.weebly.com/uploads/1/3/0/8/130874101/wepopirilo.pdf
    • https://static.s123-cdn-static.com/uploads/4484624/normal_5ff40f0822b2a.pdf
    • https://cdn-cms.f-static.net/uploads/4415770/normal_60c6d4bb2fae4.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/60860f6b-25e2-48a1-913f-ea4df3d830b8/kodak_zi8_as_webcam.pdf
    • https://uploads.strikinglycdn.com/files/bce700ec-ecfd-408f-9254-531951d57e85/how_to_raise_dermestid_beetles.pdf
    • https://uploads.strikinglycdn.com/files/b0ecfb05-79fd-4915-8b61-806ec7c998bc/jomadir.pdf
    • https://uploads.strikinglycdn.com/files/562e2b21-8b25-4a25-8f06-095cf44e293f/cch_nhn_bit_g_mi_tre_sp.pdf
    • https://uploads.strikinglycdn.com/files/ded99ff4-53e0-488d-995d-f8ebeeec9a39/dirt_devil_type_ac_vacuum_cleaner_bags.pdf
    • https://uploads.strikinglycdn.com/files/3e8863df-319f-4c12-b2a7-3de8204c0686/duzikofonufuwexanasib.pdf
    • https://uploads.strikinglycdn.com/files/e0307549-bf82-4891-8d7e-32af047ce7ce/how_to_use_free_auto_clicker.pdf
    • https://uploads.strikinglycdn.com/files/5833ae0a-5a4b-4520-ae35-99a29c7762e1/64625843028.pdf
    • https://uploads.strikinglycdn.com/files/4c7723e3-ee5d-4004-ba72-16d1c9838082/vibigolinupudalizow.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f48d.bin
89331ea0fa59a210428c99101067e1d017ec0b418a37da9c30675481d8b311b5
pdf-font-stream PDF embedded font (sfnt) at offset 0xF48D 5284 bytes
font_01_sfnt_off0001065f.bin
bc64900940f193f9f4ca7bf102fb793749e5e9e41ce419b20937cbfbf9f1a905
pdf-font-stream PDF embedded font (sfnt) at offset 0x1065F 11340 bytes