Malicious PDF — malware analysis report

Static analysis result for SHA-256 f42967332d14ac63…

MALICIOUS

PDF

61.9 KB Created: 2020-09-30 00:23:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-10
MD5: fe4d78db670148cc463a081e4ad54a4d SHA-1: 08b704fef37814d17a96293c09e7f7e1f84e925d SHA-256: f42967332d14ac6388785984a07cd0539fe66f1ef3b4e1f91bc4dce4399b5653
194 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?keyword=budget+template+free+pdf In PDF document text
    • http://lobodokev.coolanarneyns.com/uploads/1/3/0/9/130969915/f787f.pdfIn PDF document text
    • http://files.mechelsehattrick.be/uploads/1/3/0/9/130969965/bodovano_ranudazagiveda_ritox_vokukakolurog.pdfIn PDF document text
    • http://gofuwi.pbgnation.org/uploads/1/3/2/7/132711981/buwepitekuresuna.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/0416/4257/files/81965122197.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/5523/4710/files/ballin_mustard_video.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/5008/2202/files/2003699960.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/6392/7203/files/22968146464.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/1560/9252/files/bhagavathi_movie_meme_template.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0452/3986/1408/files/section_54_of_cgst_act_2020.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/9725/1235/files/sample_brag_sheet_for_college_recommendation.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/0271/6572/files/tuesday_david_wiesner.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/9229/5333/files/bilasunagirip.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/53b5b2dc-81cc-4a56-b543-07c9d7b20774/nanavazejazapudevalurato.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/01ea0bea-575a-4c01-a1a1-d71aa70300bf/29644514378.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c79e08bd-e59c-45c4-afb2-995bfae733c3/47612886424.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9921205e-5196-48db-828f-9cbb394e13ed/99647052398.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/567ece6a-6a62-416d-a531-b0bae65e5446/56654904486.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ab3a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAB3A 5232 bytes
SHA-256: 5704f4839e8801cd2e0a37c9b292ed189959ae4a464b6dc4f90ef6fd5a8176d5
font_01_sfnt_off0000bcf4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBCF4 1884 bytes
SHA-256: b413b0c3de4ac29e53c6e207da0c70674958083d30d109346f4a3e7ca8f6d720
font_02_sfnt_off0000c5f9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC5F9 10524 bytes
SHA-256: db989fad4818a745e81fd99cc3bd2157f5445be80de18c1bcd193cf5c9fb9c85