Malicious PDF — malware analysis report

Static analysis result for SHA-256 028e6dd49c35c689…

MALICIOUS

PDF

42.3 KB Created: 2020-06-16 09:20:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c1a2ee188be1b4f2d3daf71333281d9a SHA-1: f64b5e8989c40d43cdd4ce9cab8c69a27767a6de SHA-256: 028e6dd49c35c6898e260a5030dae9e2078b1ffd51d72e05e27a234467354cdc
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of embedded external links, identified as a link farm. The ClamAV detection and ML classifier strongly indicate malicious intent, likely to distribute further payloads or engage in SEO manipulation. While no scripts were explicitly extracted, the PDF structure and extensive URL list suggest it acts as a dropper or redirector, potentially leveraging JavaScript for execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9094279-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9094279-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ark.lovegodblesspeople.com/uploads/1/3/1/6/131637148/131637148.html#urdu+lughat+dictionary+pdf
    • http://kestrelais.com/uploads/1/3/1/4/131438038/sajubexumewebulala.pdf
    • http://danielaso.com/uploads/1/3/1/3/131379836/5627779.pdf
    • http://thomasdfisherphotography.com/uploads/1/3/1/6/131637043/puwubu-suvotagemekuki-vajed.pdf
    • http://eaglehealthinsurance.com/uploads/1/3/1/6/131637385/dopewimetabufuw-kegopavo-nosev-ludanafafe.pdf
    • http://74-123-78-212.mgwnet.com/uploads/1/3/0/5/130539373/zepazakutuzitum.pdf
    • http://marenhenson.com/uploads/1/3/0/6/130603793/763431.pdf
    • http://1p3.undesirable.us/uploads/1/3/0/3/130313115/gejuxize.pdf
    • http://buildyourcomputer.com/uploads/1/3/1/3/131383483/gubijeme-begofeni.pdf
    • http://suchiraconstructions.com/uploads/1/3/0/6/130604449/bilikejodesarazuw.pdf
    • http://smartcollaboration.org/uploads/1/3/1/3/131398542/janiva.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006fc2.bin
96b6be9fe40af09615133ece8cf8b2c421141f9947a41ac312f195b660dee1f1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6FC2 25744 bytes
font_00_sfnt_off000050a1.bin
13b8657cab356854e6d50d3ccdca46dcf339f5d8ddd43768898a3ae32ee47148
pdf-font-stream PDF embedded font (sfnt) at offset 0x50A1 9080 bytes