Malicious PDF — malware analysis report

Static analysis result for SHA-256 048857d6ccbb16f3…

MALICIOUS

PDF

82.7 KB Created: 2021-03-15 09:55:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3b9ca4d0920e46062148905d88376cd8 SHA-1: 434995c1529d6715c2859c8808fbb8dc667b44ed SHA-256: 048857d6ccbb16f3d2fd795d63d02b8fdc1d6c32839637b5fda4cd8781fa16d1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to domains commonly used for hosting malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of links, suggesting an attempt to distribute malware or phish users. The embedded URLs point to suspicious domains, and the ML classifier strongly indicates maliciousness. No scripts were extracted, but the structure suggests a link farm designed to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=va+26-8937+form
    • https://wivaralizufijol.weebly.com/uploads/1/3/1/4/131483386/bomip.pdf
    • https://wazolupagod.weebly.com/uploads/1/3/0/7/130775763/zaluvobetadazekifori.pdf
    • https://xiruzukigipimog.weebly.com/uploads/1/3/4/8/134865515/fudizusikerufa.pdf
    • https://zejasuvosoropaj.weebly.com/uploads/1/3/5/3/135345482/dozodubal.pdf
    • https://bexoligimes.weebly.com/uploads/1/3/4/3/134314561/nelijanefifi_paboxabowuw.pdf
    • https://nomozusosowewox.weebly.com/uploads/1/3/1/4/131453154/3112396.pdf
    • https://dojexivosofu.weebly.com/uploads/1/3/4/3/134348646/bawajokugeti.pdf
    • https://zujomesesewega.weebly.com/uploads/1/3/4/9/134902804/1229820.pdf
    • https://wilepera.weebly.com/uploads/1/3/0/7/130740018/7615919.pdf
    • https://tezenilul.weebly.com/uploads/1/3/6/0/136085996/191fdf.pdf
    • https://xamilugalaw.weebly.com/uploads/1/3/5/3/135325617/8664724.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://ranojulugonisa.rf.gd/debutotulutamurad.pdf
    • https://s3.amazonaws.com/zepifudoxapo/14057349215.pdf
    • http://dulubuli.rf.gd/nofubizizarenofisav.pdf
    • http://rufegojokod.epizy.com/call_recording_apps_apk.pdf
    • https://s3.amazonaws.com/fukezavazuj/86567899404.pdf
    • https://s3.amazonaws.com/rojalexipokadaz/sugofefopesirimoxoj.pdf
    • https://s3.amazonaws.com/mosezavor/11142338243.pdf
    • https://s3.amazonaws.com/fotojipifuzitul/35463510408.pdf
    • https://s3.amazonaws.com/buwosevax/kabalafujul.pdf
    • https://s3.amazonaws.com/sinamozagemoger/how_to_report_workplace_harassment_in_texas.pdf
    • http://bupineweso.rf.gd/dodefexa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000efe4.bin
72ad24cba809e20390c1516cc393ae36e57fffc0d70d455fd14b482653e2b081
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFE4 5580 bytes
font_01_sfnt_off000102de.bin
b81aa82c89c1503815ebfb02e494ee62cb1db1a6b16ad8f432db0da2bd22e531
pdf-font-stream PDF embedded font (sfnt) at offset 0x102DE 10888 bytes
font_02_sfnt_off00012864.bin
159427b32ed66bfbde86def5e6c2992bde67dfb25400c4000a37c9b59b949b61
pdf-font-stream PDF embedded font (sfnt) at offset 0x12864 16140 bytes