Malicious PDF — malware analysis report

Static analysis result for SHA-256 0be0d0ff5e514fb3…

MALICIOUS

PDF

45.7 KB Created: 2020-04-01 23:22:40 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 8e8d623d9104e9d0c5090bc7d8930612 SHA-1: e3f1aa05898be7543cc9bb52592aeffb349df5c7 SHA-256: 0be0d0ff5e514fb3734d5cd7ea0827de7f1f01d2240c9ffe84fffa14c1b40e2f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of external links, indicating a link farm or redirection scheme. The ML classifier strongly flagged this PDF as malicious, and the presence of numerous URLs suggests an attempt to direct users to potentially harmful content. No scripts were extracted, but the document body and heuristics point to a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://65bancker.com/uploads/1/3/0/8/130814010/130814010.html#manual+para+entender+el+juicio+de+amparo+adriana+campuzano
    • http://estatenet.ca/uploads/1/3/1/1/131163578/eae10a2d92e69a.pdf
    • http://microcompts.us/uploads/1/3/0/5/130551943/wigofebuleza-pasibow-tamigor.pdf
    • http://giftcardguy.org/uploads/1/3/0/5/130538946/residetufizaj_lekeguxap.pdf
    • http://jasonjoelharris.com/uploads/1/3/0/7/130776577/wugodudakefo.pdf
    • http://missionbluecamp.org/uploads/1/3/0/9/130968976/eed4a.pdf
    • http://detroitbeautyshow.com/uploads/1/3/0/7/130738723/sewutugaro_zunozixagujazon_zakofem_julejalexeduma.pdf
    • http://rubiconrescue.com/uploads/1/3/0/7/130739063/00a5c5c9944e.pdf
    • http://indulgeinyourbestlife.com/uploads/1/3/0/9/130969185/4bd584e.pdf
    • http://herhoosierhousehold.com/uploads/1/3/0/8/130814252/1118303.pdf
    • http://banhangthue.org/uploads/1/3/0/5/130546024/7655037.pdf
    • http://nationalsteelbuildingsltd.com/uploads/1/3/0/7/130739560/84275f4e0864.pdf
    • http://vouchermarketing.com/uploads/1/3/0/2/130272918/nunufozurive_gevomivod_ragifafoveraxur.pdf
    • http://anthonymassarotto.com/uploads/1/3/0/3/130323884/labubone.pdf
    • http://andreasdimitriou.com/uploads/1/3/0/8/130814467/wavavajewabe.pdf
    • http://growingabilities.com/uploads/1/3/1/1/131163638/b0c8f0b93e40.pdf
    • http://thecraftroomomaha.com/uploads/1/3/1/3/131398411/fonenete.pdf
    • http://whiskeydarling.com/uploads/1/3/0/8/130814467/4fac076.pdf
    • http://0negocios.biz/uploads/1/3/1/4/131483447/14c64af3.pdf
    • http://itranssupport.pl/uploads/1/3/0/4/130489763/tunojuna.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000088f4.bin
62abdaa157a768dc8e957bad58a20a647472ae9e0218c3c2cd1d87a0faec12ab
pdf-font-stream PDF embedded font (sfnt) at offset 0x88F4 9024 bytes