Malicious PDF — malware analysis report

Static analysis result for SHA-256 e78c8c6d978e2255…

MALICIOUS

PDF

81.5 KB Created: 2020-12-27 22:25:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 8b69e5d65c881227cbc946ba2ff326d3 SHA-1: 5457f8948683a092ce292ab91b24d18709842348 SHA-256: e78c8c6d978e22550dccccf6da4e8abbfb3b33324561e13675f556e0315a4eb7
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for creating link farms or redirecting users to malicious sites. The 'PDF_SEO_LINK_FARM' heuristic and the presence of multiple unknown reputation URLs strongly suggest this malicious intent. While no scripts were explicitly extracted, the PDF structure and the heuristic firings indicate it's designed to lead users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/strik?utm_term=battle+angel+alita+last+order+manga+volume+1 PDF link annotation
    • https://cdn.sqhk.co/ranotigu/KjirNfN/i_want_to_play_tag_with_ryan_game.pdfIn PDF document text
    • https://cdn.sqhk.co/xidosisew/cqgclI4/big_mirrors_for_sale_ebay.pdfIn PDF document text
    • https://cdn.sqhk.co/renapudovi/fguja5K/zombie_comando_shooting_offline_fps_mod_apk_download.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4452851/normal_5fe3c7f86e4f3.pdfIn PDF document text
    • https://xuwupeloz.weebly.com/uploads/1/3/4/7/134734270/lipeku-logurufuwe-mumale-duwogomoziziwam.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/0e08cab7-e766-4d78-8d2e-5ce04012d4eb/bizaked.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/db89c5d1-ae9d-4405-a04a-44ea681e5364/23586205217.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8039b1d2-1b40-4fb2-b53b-ab15345f1732/vezarunetoges.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6e83ba27-44fd-4af1-b260-f506663331af/dovuli.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba710955-93dd-4733-90ab-bc51feb9a0a5/bafajevituwiv.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c2515da8-35ae-4af7-b3b6-d4957e2fdebe/4839258748.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f24b2a5-26e7-4616-8cee-6246b3d8802e/belusoliwusazufikeselew.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3273a473-1072-4789-9d1f-79fdd1405398/36459583408.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c4938a64-75dd-4167-b2bf-86eb37a6d2bc/zowuj.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee4c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE4C 5428 bytes
SHA-256: bdc4b564fa444abd082f71a161572d8ee734f9b23e4be76625627ff6b752b297
font_01_sfnt_off00010101.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10101 5304 bytes
SHA-256: 822dc93c84be4216b3e812c7f767406fddfa93d6f3f31b0b90ad7f96f983ee5c
font_02_sfnt_off00011302.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11302 10940 bytes
SHA-256: 488d0f4610b3863c2ad22622274b44e80b26eac87223e59512009ae7b24b9018