Malicious PDF — malware analysis report

Static analysis result for SHA-256 041ad8bdb8661e65…

MALICIOUS

PDF

36.8 KB Created: 2020-06-04 22:04:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9f815d92f0b8eb415918702a3a09f5ce SHA-1: 54b7d7f96aed3cb25a5938705b92c0253c49f224 SHA-256: 041ad8bdb8661e657bc938520f5c35477d0d8dccea6462f3c53a5987e9f77107
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also strongly indicated maliciousness. While the document body contains garbled text and what appears to be metadata, the primary malicious activity observed is the embedding of numerous URLs, suggesting a link farm or a method to distribute further malicious content. The presence of a QR code lure heuristic further supports a phishing or social engineering attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://speelkoning.net/uploads/1/3/1/4/131453076/131453076.html#autel+ap200+user+manual
    • http://yournextheadquarters.com/uploads/1/3/1/3/131382531/pabipewidodikir.pdf
    • http://barriobites.com/uploads/1/3/0/4/130483582/juxovedazekal_lerojat.pdf
    • http://grinx.net/uploads/1/3/0/7/130738964/4773995.pdf
    • http://everestorationministry.org/uploads/1/3/0/2/130288301/kowamirarukikuxejubi.pdf
    • http://webdisk.lapakumroh.com/uploads/1/3/1/6/131636781/tusor.pdf
    • http://eportfolio.ryanstotesbury.com/uploads/1/3/1/6/131607703/jafowoxejega_nozug.pdf
    • http://speelkoning.net/uploads/1/3/1/4/131453076/terms.html
    • http://speelkoning.net/uploads/1/3/1/4/131453076/dmca.html
    • http://speelkoning.net/uploads/1/3/1/4/131453076/policy.html
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://sudevoxe.files.wordpress.com/2020/06/delusumiv.pdf
    • https://tezoduwob.files.wordpress.com/2020/06/57898192219.pdf
    • https://gozikes.files.wordpress.com/2020/06/kimixewabugiru.pdf
    • https://sunewizev.files.wordpress.com/2020/06/xawatak.pdf
    • https://pejiralitoke.files.wordpress.com/2020/06/52246007440.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000635e.bin
722f980a531094187e7869a4af38fbd40bd82481b1f7375eb32ebdbc4b5bbfc2
pdf-font-stream PDF embedded font (sfnt) at offset 0x635E 10696 bytes