Malicious PDF — malware analysis report

Static analysis result for SHA-256 c498508a78873221…

MALICIOUS

PDF

73.7 KB Created: 2021-01-31 01:16:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-04-25
MD5: aed9d53754b7cea47a0b36d75ed704ab SHA-1: c89fbb25adc55a0e926689d549fda7c9935344a3 SHA-256: c498508a78873221c69f7a55d1f7c35aebaeb0c2df1b7e4ac10a28e36748e3be
196 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/wb?keyword=download%20alarm%20clock%20for%20pc%20windows%207 PDF link annotation
    • https://mafobosapufi.weebly.com/uploads/1/3/4/5/134505980/4026984.pdfIn PDF document text
    • https://cdn.sqhk.co/zesonixiv/dRHLhRw/51497163715.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4401555/normal_5fe5e25760807.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4373008/normal_5fe39e32c358c.pdfIn PDF document text
    • https://cdn.sqhk.co/kagaxavog/ryfrmif/sogipivididogitijokum.pdfIn PDF document text
    • https://cdn.sqhk.co/sagitusat/rgfjihf/roblox_shark_simulator_codes_2020.pdfIn PDF document text
    • https://cdn.sqhk.co/vavewiminiv/dzihlji/spiritfarer_fat_for_fried_chicken.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4477630/normal_6009bd71c0f2a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4367310/normal_5fff236e5028b.pdfIn PDF document text
    • https://cdn.sqhk.co/fagisuxupinu/hhjhJpG/94706843164.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4489429/normal_5fc655e21c194.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4376127/normal_5fff50778d848.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/rilexazejuzovep/beauty_and_a_beat_cover_song.pdfIn PDF document text
    • https://s3.amazonaws.com/tawovojo/kelunuvafi.pdfIn PDF document text
    • https://s3.amazonaws.com/gezejoputiwinu/antarctic_ice_sheet_nasa.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e40a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE40A 5536 bytes
SHA-256: 837f834c6a2bdfa51a5ce4ad4b782e834ff847940c7cfe36d0a0a9f3ed72b976
font_01_sfnt_off0000f6ef.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF6EF 10360 bytes
SHA-256: f7c85f75cf4c5cbaff929e7656168dd6f9b6a74877e5aa97769350a235a81719