Malicious PDF — malware analysis report

Static analysis result for SHA-256 f47049977b739d61…

MALICIOUS

PDF

72.6 KB Created: 2021-03-08 22:52:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-10
MD5: 95d89c0745b24f0f63c1e810bab198b3 SHA-1: 57461f977e741d8f9e17e805a875ababc9955e9a SHA-256: f47049977b739d6183d5f27792df901ae23b19934d2ccfb459d27aa9b0136903
184 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/award?keyword=candy+pdf+to+word+converter In PDF document text
    • https://static.s123-cdn-static.com/uploads/4378857/normal_5fe54fb125b23.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4416331/normal_60017a311e3d1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370309/normal_5fd259f3cbe15.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4447915/normal_5fe08be3d21ab.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4481999/normal_5fda05f168b53.pdfIn PDF document text
    • https://cdn.sqhk.co/ludafojebi/gVviehg/72652520103.pdfIn PDF document text
    • http://jilavixit.medianewsonline.com/26725344143.pdfIn PDF document text
    • https://cdn.sqhk.co/vonitumefide/vPPhajj/22195515657.pdfIn PDF document text
    • https://cdn.sqhk.co/xogixute/iehdmic/among_us_mod_menu_android_always_imposter_apk.pdfIn PDF document text
    • http://bovewitavivebu.getenjoyment.net/xuwawolewunumasu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/tajimipojimo/smoothie_recipe_for_weight_loss.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89bad4e4-1d68-4119-b34f-feb788162830/sennheiser_ew_100_g4_e945.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ff255d2e-5f08-4c52-af29-6c6526d0895c/comtrend_default_password.pdfIn PDF document text
    • http://nabulegewuwal.myartsonline.com/tn_v__binh_php_tn_t_tp_15.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fdf8603b-6a94-43ef-8ae8-d43aca7ed0eb/volar_sobre_el_pantano_libro.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5b67000a-02fc-46be-931a-1e904087ea18/nanazunazudoxogakiwegov.pdfIn PDF document text
    • https://s3.amazonaws.com/tazibabebamep/buvimuwutupivefi.pdfIn PDF document text
    • https://s3.amazonaws.com/sesijesule/ashleigh_jordan_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa523ec3-7daa-4a7f-9445-99605dfecf2f/zulaxun.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/acada42b-7812-427f-9e82-8254f403defa/is_la_la_land_on_netflix_canada.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/861c9c54-b8e6-4482-a52e-563c12352867/70298340665.pdfIn PDF document text
    • http://sutexuvidag.myartsonline.com/is_eso_worth_it_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a256b0f-4657-4297-ba33-ee5d9cba95f8/51258919991.pdfIn PDF document text
    • https://s3.amazonaws.com/bokexizometun/76809123318.pdfIn PDF document text
    • https://s3.amazonaws.com/gavapozalilup/draw_for_dummies_free_download.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ddc4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDDC4 5100 bytes
SHA-256: 6bbd8036d2acb83d6caec43667dc31ea70ab038ef5885470722f4ef6f629bf54
font_01_sfnt_off0000ef4d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF4D 11464 bytes
SHA-256: e9d43d1ebfb1383e87a39e9a5026af37b0303e9d09c8f2a9ace4b18a123efda5