Malicious PDF — malware analysis report

Static analysis result for SHA-256 02e19d620ae787e1…

MALICIOUS

PDF

27.8 KB Created: 2020-05-19 02:12:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c55b6fc8e65def2827d2b2a7d755db3c SHA-1: 6598404d462d0d6a4eb47b1d6fc0bcfdf632cfc3 SHA-256: 02e19d620ae787e17d39c9ae5fc888a846a7ef2ab7e0c315fa25fcfecd178095
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection scheme. The embedded document body text also contains URLs that are likely part of this scheme. The ML classifier strongly indicated maliciousness, and the presence of numerous external links points towards a malicious intent, possibly for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9959

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://blacktreelofts.com/uploads/1/3/0/5/130550895/130550895.html#dragon+ball+shin+budokai+2+iso+usa
    • http://neuracing.com/uploads/1/3/1/4/131453574/5742623.pdf
    • http://foxboxfilms.com/uploads/1/3/1/0/131070442/3434170.pdf
    • http://cholesterolstudiesandtreatment.com/uploads/1/3/0/2/130288540/4597d0372.pdf
    • http://maupin.net/uploads/1/3/0/4/130436139/5850938.pdf
    • http://yescreditacademy.com/uploads/1/3/0/6/130605165/xisixamewutoxulito.pdf
    • http://keithart.net/uploads/1/3/0/6/130639045/9347983.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000042e4.bin
4755fea4e133f23eaf8405362ee7c33397aabfb6984afde34a4f7fdded51941d
pdf-font-stream PDF embedded font (sfnt) at offset 0x42E4 9792 bytes