Malicious PDF — malware analysis report

Static analysis result for SHA-256 a147e0f9ee788318…

MALICIOUS

PDF

50.9 KB Created: 2020-10-16 11:34:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: f46a5b7d6ee9fbdcedbe2856ce626280 SHA-1: 1646351b06cedc6b7c53ead3ee23072da0706be2 SHA-256: a147e0f9ee7883184c7c33b56506bd6c2d29974e7306fb24f51b2f0852b453e2
154 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/pify?keyword=libro+yurupary+completo+pdf In PDF document text
    • https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/rizaxigazezafasoxa.pdfIn PDF document text
    • https://xipunozelizu.weebly.com/uploads/1/3/1/3/131382486/947fd8d2109.pdfIn PDF document text
    • https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/dukojalevivemi.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365649/normal_5f8706a9ef96a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366647/normal_5f8752593247c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/849d9d11-19ea-435d-a89c-db616862cd22/pikiwizopupubefoso.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a6f4126-2379-4f30-9742-d0d6c9b493b5/fixotilawudifolomakideg.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/badba3b5-72b1-4691-9e4a-9508425dc6d6/70211030193.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/876a42ea-858d-4ac2-b78e-1d0af3a9dcec/difun.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e102b278-1228-44c7-a761-e4699a83623f/8858220596.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/513263cf-fe0f-433e-898c-7614c5dc53cd/lozaroruxavefakefaved.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/85084f8a-cab2-4e4b-9807-144549e773bc/ropagimeminuk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7094320-8e77-402e-a184-6f3e069d6958/33348020774.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e71532c9-2c14-4d03-ada2-dc25777ab75f/xiwewivofipim.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a472dbd1-80dd-474e-a70f-0aa53fc2b418/mexezizurapiz.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0484/6623/1446/files/3_meters_above_the_sky_book.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/1713/4502/files/36299867888.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000876f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x876F 5308 bytes
SHA-256: f0e6d9fdcebfb632dfaa424e32ce806e6187e783bbd5145c5ba1908fc8975e73
font_01_sfnt_off00009968.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9968 11528 bytes
SHA-256: 5d587c32713c4a452afa162d464c3a51e850f2f17f08fb3afb04f51d24e41aba