Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca0c34ad4c67d056…

MALICIOUS

PDF

88.9 KB Created: 2021-01-13 17:52:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bfe533ef01cd6639af3eb3b6ee231e53 SHA-1: eed061d3a0210b686a85a36a38317b4ac3fd8969 SHA-256: ca0c34ad4c67d056ad1bb986410bd6a049ee9c94828d6064d64c3eaccc08b489
224 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file contains multiple embedded links, with one specifically pointing to a known malicious redirector. The heuristic 'SE_MFA_LURE' indicates the document's content is designed to trick users into providing sensitive information, such as one-time codes or MFA approvals, consistent with credential harvesting. The presence of embedded URLs and the nature of the lure suggest an attempt to facilitate phishing attacks.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/aws?utm_term=cisco+anyconnect+vpn+client++exe
    • https://site-1167954.mozfiles.com/files/1167954/kung_fu_fighting_game.pdf
    • https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
    • https://cdn-cms.f-static.net/uploads/4389104/normal_5fb60c83035b4.pdf
    • https://cdn.sqhk.co/zefipuvuwifi/fUlK1ge/nurusarududesu.pdf
    • https://cdn.sqhk.co/sileluzorupo/t5rhhjh/herbal_home_remedies_and_natural_cures.pdf
    • https://static.s123-cdn-static.com/uploads/4446512/normal_5ff311b758167.pdf
    • https://cdn.sqhk.co/xafileme/1iijeid/power_audio_pro_music_player_free_apk.pdf
    • https://zolulosix.weebly.com/uploads/1/3/3/9/133986826/806755.pdf
    • https://site-1177214.mozfiles.com/files/1177214/jakuvorudamagapaka.pdf
    • https://cdn.sqhk.co/tororukiwuri/hjcggic/birdy_gray_size_chart.pdf
    • https://cdn.sqhk.co/jivonotiso/jfgijfz/screen_lock_time_password_app_download.pdf
    • https://cdn-cms.f-static.net/uploads/4373509/normal_5fbd9104afc4c.pdf
    • https://wawupibinotab.weebly.com/uploads/1/3/4/9/134900246/jutek-bizatomo-jiworizef.pdf
    • https://sinaxerepedosuj.weebly.com/uploads/1/3/1/3/131398545/lekazokuwi.pdf
    • https://cdn-cms.f-static.net/uploads/4379626/normal_5fe79d2e10ded.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3f4.bin
43a62e71a0253d103eb5b640a7d64012de0de5d91b99f85555f7362ff56e2839
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3F4 20112 bytes
font_01_sfnt_off00011f61.bin
87e579727bfa1b95ddb45358bfd097ebac975d3bf26760acff830ccf66487b68
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F61 4964 bytes
font_02_sfnt_off0001306c.bin
c453fa65bc1272d0ede6a661e437fe444ae4a2fb94e3a0ecdf1db29dd77ed59a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1306C 11840 bytes