Malicious PDF — malware analysis report

Static analysis result for SHA-256 60a237254910f70c…

MALICIOUS

PDF

73.3 KB Created: 2021-04-02 16:55:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fe77290dd520b39115cc4ec13c46e1cf SHA-1: db68a27d045776c39ffb6128923f35f7aa57e009 SHA-256: 60a237254910f70cd7495ff095944ac3146630d910227186478c9ef571660f19
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one prominent URL pointing to a suspicious domain that appears to be part of a link farm. ClamAV and ML classifiers indicate malicious content, specifically identified as a phishing trojan. The document body, though heavily obfuscated, contains keywords related to public administration and strategy, suggesting a lure for phishing or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/award?keyword=administra%25C3%25A7%25C3%25A3o+p%25C3%25BAblica+pdf+estrategia
    • http://copyright-rules-help.com/83943596321nbgtn.pdf
    • https://cdn-cms.f-static.net/uploads/4495837/normal_6048aa6131be7.pdf
    • https://cdn.sqhk.co/rapowipijes/jaii1Vd/mandalorian_bebe_yoda_mobile_wallpaper.pdf
    • https://cdn.sqhk.co/tarozawowe/Fgdiejj/jibibomigakezolosemep.pdf
    • http://lnstagramcentre.net/john_lewis_radio_controlled_alarm_clock_instructions39paf.pdf
    • https://cdn-cms.f-static.net/uploads/4392474/normal_5fd78ebe48905.pdf
    • https://cdn-cms.f-static.net/uploads/4380674/normal_6049a4c8b4c49.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://8e6fe9cb-6e01-49b8-a8bf-add1d7538daa.filesusr.com/ugd/4e948c_b9545d807ca84728946cf693b9eed611.pdf?index=true
    • https://d8d691c7-cf48-432b-bece-a54604b57851.filesusr.com/ugd/1e3a4b_1a93e3a04aca4a8f931ed275b320c885.pdf?index=true
    • https://s3.amazonaws.com/puretulenuza/jiwuxodit.pdf
    • https://s3.amazonaws.com/sajatofubote/ketogenic_diet_book_free.pdf
    • https://s3.amazonaws.com/wudibirewuduto/pomimonuv.pdf
    • https://d8acad56-eb9a-42d1-a06c-a695c5b02328.filesusr.com/ugd/0ad6c7_eecfe20ae0354da7b422d06e09e2798e.pdf?index=true
    • https://s3.amazonaws.com/kukupunopedon/sinupoxosor.pdf
    • https://s3.amazonaws.com/zupenafud/52893732757.pdf
    • https://aa5f33e9-793b-4807-a257-9eac84d314d0.filesusr.com/ugd/aa57b2_43d2f0ac2bae44a6a136f133365b4b03.pdf?index=true
    • https://s3.amazonaws.com/sabegokek/walaviraju.pdf
    • https://s3.amazonaws.com/genedonapubefe/what_to_do_if_paper_shredder_is_stuck.pdf
    • https://s3.amazonaws.com/kukazowox/20850442222.pdf
    • https://c140f178-ee45-427e-91fe-a3c5f821f67e.filesusr.com/ugd/ebc5f9_3ccc599188c34c64897c939fae6be009.pdf?index=true
    • https://s3.amazonaws.com/xeroguru/lowdermilk_beach_red_tide_report.pdf
    • https://s3.amazonaws.com/juliziwojatige/telefono_para_reportar_alumbrado_publico_zapopan.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dd03.bin
d3e3e90f5e5ea3d8a0dc76ffbd860192539c418f962dc86bc0588fdc943dd751
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD03 6220 bytes
font_01_sfnt_off0000f104.bin
0bd0ffcf292d17986282c0f01a7b0cfbb74d00b5c130826d7e4b03629bc3923e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF104 11600 bytes