Malicious PDF — malware analysis report

Static analysis result for SHA-256 b73f3165a8da1c7e…

MALICIOUS

PDF

72.1 KB Created: 2021-03-06 13:23:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-04-25
MD5: 66b15a29be829cca6e29456af50f7bd2 SHA-1: d54edc8d880177960bd496de96f689597d42daa8 SHA-256: b73f3165a8da1c7e385c6d2e8cbca551f40ef97e13d72aca7aef312fc570f4d4
196 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=d%2527link+2750u+firmware+update PDF link annotation
    • https://dasujodiket.weebly.com/uploads/1/3/4/4/134481559/kexuzofu_riwimonerako_pidasagereraz_jidezujavasituf.pdfIn PDF document text
    • https://botironuz.weebly.com/uploads/1/3/1/3/131380999/tegev.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386089/normal_5fd13387e8a54.pdfIn PDF document text
    • https://cdn.sqhk.co/puvegipuros/jjadwid/sipinu.pdfIn PDF document text
    • https://cdn.sqhk.co/bepemuno/ijcZhcL/sikedisijevobagajobinabif.pdfIn PDF document text
    • https://cdn.sqhk.co/nakunadubux/fejdhfH/mosanesafinomafusis.pdfIn PDF document text
    • https://cdn.sqhk.co/kakapoxavu/6jhRif6/gusunosulamoninop.pdfIn PDF document text
    • https://cdn.sqhk.co/seponidozit/hjhgdjf/44864626947.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4457582/normal_6021f9121a0c9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4500878/normal_603df38f652fe.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4455645/normal_5ff888b808498.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/1ef01a90-b61b-419a-a1fa-7dcbd6709df9/42198802478.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/af0c94a8-699b-4693-8d7f-63fb033f7cb8/2016_harley_davidson_street_glide_owners_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/788e5da6-0cfa-4bee-b6a4-5de2cb77b876/33231522708.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4f0e10c2-18f6-4fb1-b07a-3dd82376db65/big_little_lies_trailer_deutsch_staffel_1.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc43c003-2846-4a7a-bc1c-5ad4f5413ad0/batosabegulidoz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/048d71f1-cf61-45e1-a748-e0d6c679e71e/moultrie_game_camera_user_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5d040e36-618b-457e-9843-433f45686fb2/sasewefavaves.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d1ba4815-70d6-4f16-8f2e-18a367500237/omron_body_composition_monitor_bf508_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/915700c3-2113-4124-baa9-f3476d219b09/ariens_520_snowblower_belt.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c1b7e22f-da19-48ba-b4ad-815edaffade1/tuvaxetodan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/076e5996-362f-4e83-96af-59b18f8455cd/dr_terry_wahls_protocol_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3eafe8b1-2bd5-41c5-b429-3aeb1ae7de57/50329374780.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d91f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD91F 5676 bytes
SHA-256: 7299e5e97487c673559f7f0e18d1806e220db0fee602cafdf068c79e42eece02
font_01_sfnt_off0000ec90.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC90 10832 bytes
SHA-256: 4d3e34a6865f1fe85ba444dc5ec1567ff85073066dd6168040638bc9ce3e2ebd