Malicious PDF — malware analysis report

Static analysis result for SHA-256 0c246c60ce7beabc…

MALICIOUS

PDF

74.9 KB Created: 2021-03-18 04:33:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ce54e7928c36f5fc6c2453e750731976 SHA-1: 7276039285a375a82a75af9d4ddf79ccf60d3574 SHA-256: 0c246c60ce7beabc8be5e1e95ec52c0bb2c51f09a549a2963b726a7612ff900e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection and ML classifier also flag this file as malicious, specifically as a phishing trojan. The presence of numerous unknown-reputation URLs suggests a coordinated effort to redirect users to potentially harmful content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/award?keyword=anabasis+greek+pdf
    • https://cdn.sqhk.co/lijuwezasip/cgegdxo/71997090294.pdf
    • http://apsdd54gfv.xyz/how_to_reset_maintenance_light_on_2014_prius_ve0hou.pdf
    • https://bobugebajagon.weebly.com/uploads/1/3/4/6/134682349/ed0fea051cec764.pdf
    • http://alex-chekalev.com/4421587775126ddv.pdf
    • https://sijudunewofas.weebly.com/uploads/1/3/4/6/134696620/zirosojiko_rulal.pdf
    • http://bio-ita.fun/jotawipugesenufo99mkd.pdf
    • http://persequen.com/sheltered_workshop_porterville_californiaqdc9v.pdf
    • http://it50off.pro/texotasavurinugobarelajak8ez3.pdf
    • https://kasezikibojeg.weebly.com/uploads/1/3/1/8/131871727/2141618.pdf
    • http://com-signto5.xyz/55885168294gwl34.pdf
    • https://zojufagilazit.weebly.com/uploads/1/3/0/9/130969654/vabusimefuzu.pdf
    • http://prequester.online/parches_chenille_personalizados_parag3u4z.pdf
    • http://mini-cam1.club/real_followers_pro_apk_latest_version4eyqo.pdf
    • https://midigoxu.weebly.com/uploads/1/3/4/0/134000126/5755902.pdf
    • https://tinabatof.weebly.com/uploads/1/3/0/7/130776088/bazanebakojezeva.pdf
    • https://cdn.sqhk.co/suwapipejob/igicggf/95651998065.pdf
    • http://winoorama.website/ferokitirejoztu4je.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://61249681-e2d1-4375-841a-b3723294d79c.filesusr.com/ugd/3d514e_be8ba160925f46b8a0723b4b7bf5793b.pdf?index=true
    • https://7404da97-7fcf-4d5f-9d5f-3f8644e6773a.filesusr.com/ugd/35f767_b46a0598250e4206bef794af1deb2ca0.pdf?index=true
    • https://6e229dea-1f83-4be8-8cd3-388eabd4f5e3.filesusr.com/ugd/1cfe37_aeb9244a074f439e9547dd55876e849e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e64d.bin
079868c43f9874220355d2e0374f773bfd580de6ded8b2c212c682a602d3e49b
pdf-font-stream PDF embedded font (sfnt) at offset 0xE64D 5368 bytes
font_01_sfnt_off0000f89e.bin
81f2e5f11fafcc2330f135842d2c4d041445d81853600c251ac3dbd0a9422b5a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF89E 11460 bytes