Malicious PDF — malware analysis report

Static analysis result for SHA-256 14cc0f88f826383d…

MALICIOUS

PDF

74.5 KB Created: 2021-03-14 23:41:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8a6fd56df97d5fb417a2ad203747b7ab SHA-1: 8e4e0d6ee7912438e58afd3d3e7e8351a7575784 SHA-256: 14cc0f88f826383d7921ddc86e5854324bc50c040b163133a413109f44299719
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to Weebly-hosted PDFs, suggesting a link farm designed to improve search engine rankings or distribute malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. No scripts were extracted, but the PDF structure itself facilitates the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/wix?keyword=t-sql+fundamentals+3rd+edition+pdf+free
    • https://wesuzimowigimeb.weebly.com/uploads/1/3/4/7/134745326/bcea1b.pdf
    • https://naduvita.weebly.com/uploads/1/3/5/9/135973463/6499226.pdf
    • https://bedaruwi.weebly.com/uploads/1/3/5/3/135326402/e46220f.pdf
    • https://welaruno.weebly.com/uploads/1/3/5/3/135325412/fee0d4a03d.pdf
    • https://safamitiwifiro.weebly.com/uploads/1/3/0/7/130739579/cbb17947.pdf
    • https://digigabatafer.weebly.com/uploads/1/3/5/9/135995708/nulotiti.pdf
    • https://pixizibonemitu.weebly.com/uploads/1/3/1/3/131382366/fowis.pdf
    • https://jovuwimuj.weebly.com/uploads/1/3/0/9/130969820/5266245.pdf
    • https://jotowaviroretog.weebly.com/uploads/1/3/4/6/134604658/bulaketigode_fopotibu_gilin.pdf
    • http://mepowixodudod.22web.org/what_can_i_say_to_my_nephew.pdf
    • http://sawawobutexukut.iblogger.org/pebasowokarazanixala.pdf
    • https://jebunofom.weebly.com/uploads/1/3/4/4/134468214/mozelunim.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://c064424b-11a8-4e39-a524-24a74bcd733d.filesusr.com/ugd/54e393_25eba16a92224bb5a6a32a0abd35a3d7.pdf?index=true
    • https://s3.amazonaws.com/viwoxuz/pijevexutorovobe.pdf
    • https://61069a5e-3c5f-4884-a3c7-8c7552058b74.filesusr.com/ugd/0789d5_feef409c7058496b924ad9f56a6930a7.pdf?index=true
    • http://xibiwoziveva.epizy.com/turkey_pastrami_nutrition_guide.pdf
    • https://s3.amazonaws.com/julaxel/adobe_flash_player_11._2_android_free.pdf
    • https://s3.amazonaws.com/fujadabez/difficult_linux_interview_questions_and_answers.pdf
    • https://40e214c1-1950-44e8-a195-e2c6eeb23253.filesusr.com/ugd/a517f4_f181dd8126774c8ca5ef8c0c796926fc.pdf?index=true
    • https://s3.amazonaws.com/jizubisetebof/carabinieri_uniform_kaufen.pdf
    • https://27dd58ca-3bab-4825-b0a2-cb75a9f796de.filesusr.com/ugd/aba4c5_e1fec28de84c4b68aed61746ad82d6ed.pdf?index=true
    • http://jasigobup.epizy.com/sijusuxij.pdf
    • http://luniwopekesoto.rf.gd/introduction_to_carrier_ethernet.pdf
    • https://s3.amazonaws.com/davolazupivowi/50456343544.pdf
    • https://07d68bf2-0661-47e2-9ffe-eae068a071af.filesusr.com/ugd/fef806_faa651a0e1f743ceb2f3c2e573bc0da7.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d5b4.bin
05c78f11175a34304b298f7c32c730038f9d2010ac448e6a77a0e58c18d25806
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5B4 5340 bytes
font_01_sfnt_off0000e7c0.bin
b26d85a08c56564458d11502f6fb6ad8be8b71c1591f979a7735b81928b70a69
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7C0 10536 bytes
font_02_sfnt_off00010bd3.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BD3 4324 bytes