Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9eefcdac16880e7…

MALICIOUS

PDF

43.7 KB Created: 2020-11-09 11:14:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-01-23
MD5: a4b6b3ff0b6bd9de1ee6583ee6aa84ee SHA-1: 4e13a0a3670c1322a8b0ca932716790ec847f93a SHA-256: d9eefcdac16880e775498bb88ac9bb06f8c645027df4ccd3ae18075e1e27ace0
134 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/123?keyword=bakemonogatari+episode+13+watch In PDF document text
    • https://cdn-cms.f-static.net/uploads/4369519/normal_5f8f64a26c8d7.pdfIn PDF document text
    • https://pujawuto.weebly.com/uploads/1/3/4/5/134588096/xakusapogu_felugofajo_vitevej_wuditedeb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379029/normal_5f917d7da3c82.pdfIn PDF document text
    • https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/f07ba3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365656/normal_5f87625e65f6e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4448746/normal_5fa289f235946.pdfIn PDF document text
    • https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/5721191.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zunaporam/parrafo_spanish_translation.pdfIn PDF document text
    • https://s3.amazonaws.com/vojapu/ford_ranger_2002_repair_manual_free_download.pdfIn PDF document text
    • https://s3.amazonaws.com/nalifij/chinese_sentence_structure_examples.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36aeedb6-3a8a-4655-ab41-d9a50da4a9f0/pidivufus.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c9f21a7a-8581-4cdc-b13a-68ba1cf177f0/lurenuxuz.pdfIn PDF document text
    • https://s3.amazonaws.com/gewuwasi/51003036820.pdfIn PDF document text
    • https://s3.amazonaws.com/mejados/jarisil.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6a75313c-15b4-46ea-91d9-0a5a3e972514/72272604729.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9eaf7deb-b854-4d7d-8131-aa12beec0812/kabixemadezata.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d0201ba-8cd1-4520-a117-e5a90f2f2608/20940221483.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x69AF 5876 bytes
SHA-256: ee87e7fb92a73e6c9519b0a81c8b25ac2b9c0df84229634c2f4dcc378727959d
font_01_sfnt_off00007da9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7DA9 10740 bytes
SHA-256: 870923ef92725db1a693a82e9fa1ddacdb0eef04bcd4fc31ae1d29003baf3cae