Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2063ece42c46d8f…

MALICIOUS

PDF

79.3 KB Created: 2021-03-10 09:21:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1ae86eb04069c1453d2c2649ad68f6c1 SHA-1: 2f6009d8798a3a8453527def1414fa3c82cb1420 SHA-256: e2063ece42c46d8f566a7a3e275d3a657d18792e6055a068f3df4b586893f388
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious intent. It contains a large number of external links, many of which are likely part of a link farm designed to manipulate search engine results or distribute malicious content. The primary malicious URL identified is https://lozipotod.ru/123?utm_term=minions+full+movie++in+telugu, which is likely used for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=minions+full+movie++in+telugu
    • https://cdn.sqhk.co/loganidob/aY42hgq/26831331670.pdf
    • http://retamos.mygamesonline.org/gorabado.pdf
    • http://50offshop.info/18620831250gse8p.pdf
    • https://cdn.sqhk.co/dobexesi/jbOQ7AS/61849377786.pdf
    • https://cdn.sqhk.co/tadeketoxab/BFhdqJb/light_ball_pokemon_emerald.pdf
    • https://cdn.sqhk.co/nexetifosam/shhJhhp/kulivoxapinegefit.pdf
    • http://roxedizusugu.mywebcommunity.org/several_short_sentences_about_writing_quotes.pdf
    • http://elerctum.org/healthstream_elite_treadmill_manual88mpw.pdf
    • https://cdn.sqhk.co/misumirotoj/ikejehg/65560899119.pdf
    • https://cdn.sqhk.co/xibetevoxaj/igO4Gfj/51118074224.pdf
    • http://ejinaya.com/4043234008wt62w.pdf
    • http://rilomenininun.getenjoyment.net/abnormal_child_psychology_7th_edition_free.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://88749095-6fd7-453f-8e8a-15b48fe47dd1.filesusr.com/ugd/e4d7df_5789f5a40728419aa6db1329f4529621.pdf?index=true
    • http://vawofirulev.myartsonline.com/breast_cancer_questionnaire.pdf
    • https://3f5765b5-411c-4b28-96d1-a1e3b219bcee.filesusr.com/ugd/ca847e_86d625b7d5894229893db12e82a84299.pdf?index=true
    • https://8dfd47f4-e591-4377-92a3-bdbf91d41e5a.filesusr.com/ugd/a58b01_50fffe24ebf148998bfbce3b3cafd5e7.pdf?index=true
    • https://5a4e7950-e122-4b3c-9cf7-894e7f5b1216.filesusr.com/ugd/76aeb6_01bfa1e60281489e9f0a93ace745e722.pdf?index=true
    • https://59cf682b-6680-4a08-8b8d-0472bab64ef7.filesusr.com/ugd/d7d6cd_082622fa3d6a48788629c8485f3f181a.pdf?index=true
    • https://86b7bb9a-6a0b-496c-a062-e8aa60c365d0.filesusr.com/ugd/dcf311_3c6ccdf0fa1240029d9246113ec3d5e0.pdf?index=true
    • https://e0eedba4-cf99-4c42-97f5-d3f9ae5832dd.filesusr.com/ugd/e36ea7_64b4e352259c4da7b27766fd64e7b1dc.pdf?index=true
    • https://cccd2283-d272-450a-840b-6541230ebad2.filesusr.com/ugd/5de1df_19a346208495447d95a01a8a4a32a23e.pdf?index=true
    • https://1a447ccf-a6a5-490c-ad31-399ae8169532.filesusr.com/ugd/cf5184_acba94ddfae24e81b457a5eda9434a93.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e208.bin
5e93af536a98f08d3a9af9997a9795f712a41903ba345efac0cfd3b670d3d801
pdf-font-stream PDF embedded font (sfnt) at offset 0xE208 4848 bytes
font_01_sfnt_off0000f294.bin
a562fc87f48ff4d63858b661f0d1146572f9bbef911645ea99171e5bdbf2bb11
pdf-font-stream PDF embedded font (sfnt) at offset 0xF294 11472 bytes
font_02_sfnt_off00011913.bin
25a5e6c7c9cd73e1730f271d334b71b3c0ac6385951e3737251623a68d8eef5c
pdf-font-stream PDF embedded font (sfnt) at offset 0x11913 16160 bytes