Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a7408d2a232b8b8…

MALICIOUS

PDF

57.4 KB Created: 2020-04-03 09:15:46 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 75b387e85f0d7e9caa1807d7f4b78da4 SHA-1: b403c86eda83caa0c98c89234390e7e2e75f9a1d SHA-256: 0a7408d2a232b8b851334878ac75c92a398bf2e0b49651a71065992d97547e93
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, a common technique for SEO poisoning or redirecting users to malicious sites. The ML classifier strongly indicated maliciousness, and the presence of numerous external URIs supports this. The document body, though containing garbled text, includes a URL that appears to be a lure for a recipe, likely to mask the malicious intent of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://joshleephotojournalist.org/uploads/1/3/0/6/130620845/130620845.html#how+to+make+coffee+ice+cream+in+cuisinart+ice+cream+maker
    • http://aggressivelyintelligent.band/uploads/1/3/0/6/130639931/977764.pdf
    • http://summitatrailroadsquare.com/uploads/1/3/0/3/130313605/gasolok-rezekukogavuv-punewutut-jetekezulazub.pdf
    • http://brydgescpa.com/uploads/1/3/0/7/130775666/7112762.pdf
    • http://nepaawakening.net/uploads/1/3/0/4/130483552/46c8412324a02.pdf
    • http://engelssolutions.com/uploads/1/3/0/7/130776326/2526483.pdf
    • http://cinderalleystore.com/uploads/1/3/0/3/130313289/nekafizes.pdf
    • http://kapserenite.com/uploads/1/3/0/4/130492038/xatetibadawa_tamapado_sawerojunu.pdf
    • http://mcbroomconsulting.com/uploads/1/3/0/8/130813885/5000078.pdf
    • http://lynnespaintings.com/uploads/1/3/0/6/130639949/6485098.pdf
    • http://manlycode.com/uploads/1/3/0/6/130604848/49c7cd6a8d7f0db.pdf
    • http://kbrotherton.com/uploads/1/3/0/7/130739653/rozopekekifezuwog.pdf
    • http://betteryet.net/uploads/1/3/1/0/131071297/zozajadixotudikaja.pdf
    • http://gamefortimestocome.com/uploads/1/3/0/6/130604191/2fd39dd35c8.pdf
    • http://youngfutures.net/uploads/1/3/0/7/130775506/1651908.pdf
    • http://warpub.com/uploads/1/3/0/8/130813897/4963648.pdf
    • http://maijoycoltd.com/uploads/1/3/0/5/130551342/d6f4d594e0ea9.pdf
    • http://mehereen.com/uploads/1/3/0/6/130604086/degokomireruno.pdf
    • http://yourkstspot.com/uploads/1/3/0/5/130539170/8880314.pdf
    • http://delilahyu.com/uploads/1/3/0/5/130539182/6307966.pdf
    • http://lamplepost.com/uploads/1/3/0/5/130588799/mawevabesuru.pdf
    • http://newhampshireantiquecoop.com/uploads/1/3/0/5/130551536/besunotif-zabokub-maxunev-segap.pdf
    • http://mallardx.com/uploads/1/3/0/6/130604649/2651889.pdf
    • http://attorneyspacesharing.com/uploads/1/3/0/7/130738541/6409371.pdf
    • http://nara.cafe/uploads/1/3/0/6/130604541/winofufolibitute.pdf
    • http://tj-travels.com/uploads/1/3/0/5/130539642/fa901aae0d3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009ffb.bin
c96e3a7bb3d5d5093b39e24b832ac6c295d26b6345719d638e382bc6547f3cb0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9FFB 7880 bytes
font_01_sfnt_off0000bea6.bin
5d1d7ccab9cb9088b8dc7143fe7bcd31d83ae6a879e9004c8e90ea8174e81246
pdf-font-stream PDF embedded font (sfnt) at offset 0xBEA6 16296 bytes