Malicious PDF — malware analysis report

Static analysis result for SHA-256 05198bf9a2592f8a…

MALICIOUS

PDF

31.6 KB Created: 2020-03-29 12:37:41 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 2e1750ad0be6f59a6876be3ca2f750ad SHA-1: 502dd1653350eed0c3c986711286a540e13bdd6d SHA-256: 05198bf9a2592f8ad8e342a647d6be9005716b5ae63257d7e250687f7e770c24
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness, and the PDF structure suggests it's designed to host a link farm. While no scripts were directly extracted, the presence of numerous URLs points towards a phishing or content-luring attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lamee-dark-version3-de.devsite-1.com/uploads/1/3/0/8/130813883/130813883.html#derecho+internacional+publico+juridicas+unam
    • http://kingofpowerwash.com/uploads/1/3/1/3/131382430/kejupeki.pdf
    • http://waspconsulting.services/uploads/1/3/0/3/130323453/7167545.pdf
    • http://rachelheater.com/uploads/1/3/0/4/130477702/8607736e5fa5.pdf
    • http://absolutepaintingclt.com/uploads/1/3/0/3/130379181/zelokadavekikul.pdf
    • http://thejob-blog.com/uploads/1/3/0/6/130621703/67c278d2c21eb2.pdf
    • http://ankhor.shop/uploads/1/3/0/4/130483804/ef9b93ba09c1.pdf
    • http://jennajeslis.com/uploads/1/3/0/7/130739038/4592371.pdf
    • http://celestialinspirationsstore.com/uploads/1/3/0/7/130776304/dixane-xabijekez-gonawufug.pdf
    • http://yemencoffeeboard.net/uploads/1/3/0/5/130590209/sulonisagowa.pdf
    • http://tobinreesefineart.com/uploads/1/3/0/6/130621467/masozulo_zomemi_gifiweruwinido_jovikewolige.pdf
    • http://daviscreativeartstherapy.com/uploads/1/3/0/7/130738970/sivulufalop-pebuledef-xajezetumajifud-sidamig.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005546.bin
9d2ecaa0602c00f3006659d45acb3afdffc23e83f207724a87782fefc6064da0
pdf-font-stream PDF embedded font (sfnt) at offset 0x5546 7064 bytes