Malicious PDF — malware analysis report

Static analysis result for SHA-256 fdc7a94ac217023b…

MALICIOUS

PDF

40.0 KB Created: 2020-10-03 06:57:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-19
MD5: b27b20c58472f43e8f8d7d17f0a3d855 SHA-1: e7f7dbfff0c1cb99e9c4437c75bfefa4ddd38032 SHA-256: fdc7a94ac217023b1b58997100e366efdd37bfa134a10c9b705623d9e7ebd8d9
122 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=alternate+fingerpicking+exercises In PDF document text
    • http://files.salonsuitesjessica.com/uploads/1/3/2/6/132696323/tezugi.pdfIn PDF document text
    • http://fitar.ncc-tu.org/uploads/1/3/0/7/130776021/1241865.pdfIn PDF document text
    • http://files.asiaklik.com/uploads/1/3/0/8/130814984/ba9b8c1ced46ad1.pdfIn PDF document text
    • http://files.goldenbridgesschool.org/uploads/1/3/1/6/131636969/3018873.pdfIn PDF document text
    • http://files.clairederriennic.com/uploads/1/3/1/3/131398123/fuvib-kusup.pdfIn PDF document text
    • https://site-1037176.mozfiles.com/files/1037176/wedox.pdfIn PDF document text
    • https://site-1036633.mozfiles.com/files/1036633/83119994144.pdfIn PDF document text
    • https://site-1037143.mozfiles.com/files/1037143/niguzukodorazuzoxijep.pdfIn PDF document text
    • https://site-1037033.mozfiles.com/files/1037033/6597053177.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/6eeaa168-814e-48f4-8a46-7f48afe936dc/91332122711.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f860f6a2-b92c-4801-bc13-bb9b4b477e8b/64587200800.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/77788ae9-c3e3-4ad7-9a34-ea76d5463c2f/jurevejifejik.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e772da8-87e1-4058-9def-960d59797e32/tupuraji.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1541e45-c99e-4b92-9338-ad67f94795b1/tidufanigototofo.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0481/3422/6069/files/nuvofi.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0437/3368/0282/files/gebiwofififikolowoposib.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/1322/6143/files/next_step_counseling.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006748.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6748 5304 bytes
SHA-256: 9c88cbcc73f1f7a66b2d9d70d8ff5ef333b121d4c9997bfe7f791cefe604486e
font_01_sfnt_off00007972.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7972 10264 bytes
SHA-256: 9874a252629fe0ce79b5509e3f5d38ba3cfa36fe4c71ff64f953048967e51067