Malicious PDF — malware analysis report

Static analysis result for SHA-256 c35c2b928dc203dd…

MALICIOUS

PDF

68.5 KB Created: 2021-03-01 18:59:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-15
MD5: a42a5685c21a6292a69b0652c2373fdc SHA-1: 7f52aeeaf0d1f521d575d76a9ab31570518f5da6 SHA-256: c35c2b928dc203ddfb30411b41d89c97d6ba504300ccd0799e561bdae8aa8dc2
136 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=powerstroke+6800+generator+with+honda+engine PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4381988/normal_6004d52a91ce0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4472475/normal_5fddcdba6d242.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412895/normal_6038364d598de.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4485454/normal_6002a8c7886d7.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4383689/normal_6000b84039016.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393348/normal_5ff0336a6904e.pdfIn PDF document text
    • http://formblckr1.xyz/dryer_sheets_alternative_sploofpnn5r.pdfIn PDF document text
    • http://pinegobojefo.getenjoyment.net/94631218960.pdfIn PDF document text
    • http://prizinsta24.space/schema_boite_a_fusible_transporter_t41bdyd.pdfIn PDF document text
    • http://sakulog.sportsontheweb.net/69553370317.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4388613/normal_5ffc8c5bc668e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451208/normal_602bb56d447dc.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fidefofudi/how_to_draft_a_commission_agreement.pdfIn PDF document text
    • https://s3.amazonaws.com/nawuvud/panipenaxisezomo.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cdb7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCDB7 5700 bytes
SHA-256: 7fdd4ef925315033aa2293bd4eb8e5dc599fa6f80944081c4e1cb1d210c7726e
font_01_sfnt_off0000e12a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE12A 10540 bytes
SHA-256: a38bd6572fd90f59d61396ac0cea99e0ccd623efcfac3870a9eabfef11dbc36d