Malicious PDF — malware analysis report

Static analysis result for SHA-256 0dfc0d8985be1010…

MALICIOUS

PDF

48.2 KB Created: 2020-03-20 05:57:55 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5f205dba79a8749d0bfe12b3cc114bc4 SHA-1: 5e79491f900e81741e3e97f2b6db732edb4973eb SHA-256: 0dfc0d8985be1010dab04002a0b5775a95d5d8a4b124d40515e2416e8734d2d2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. The document body, though partially corrupted, contains a URL that points to a potentially related HTML file, and the majority of the extracted URLs are PDFs hosted on various domains, suggesting a link farm or content distribution network for malicious files. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gabrielarodas.com/uploads/1/3/0/7/130738620/130738620.html#the+dead+sea+scrolls+bible+the+oldest+known+bible
    • http://centreelmos.com/uploads/1/3/0/7/130775685/fimizaduw.pdf
    • http://savemyday.co/uploads/1/3/0/3/130323167/jobakenajafefil.pdf
    • http://vrarcadeconference.com/uploads/1/3/0/6/130604616/422666.pdf
    • http://casbenefits.com/uploads/1/3/0/5/130539783/5791727.pdf
    • http://payperlessforms.com/uploads/1/3/0/6/130603891/zadoguwila-liloj.pdf
    • http://ajactive.net/uploads/1/3/0/8/130814526/gisekimefuberuso.pdf
    • http://oceanviewvillagesf.com/uploads/1/3/0/2/130270742/kubafawezijit.pdf
    • http://ardentnetwork.com/uploads/1/3/0/2/130287527/vufiv.pdf
    • http://www.nolagirlcustomcreations.com/uploads/1/3/0/4/130483276/595926.pdf
    • http://motofototours.com/uploads/1/3/0/6/130604255/6762875.pdf
    • http://www.keto-boost.com/uploads/1/3/0/3/130323803/xutikenovox.pdf
    • http://myelitestaffinggroup.com/uploads/1/3/0/2/130288630/5854514.pdf
    • http://howiconnect.net/uploads/1/3/1/1/131164364/4f74bf.pdf
    • http://www.grasbeinter-design.com/uploads/1/3/0/8/130874241/duruzog-sijurifedoj-mofepuvemu-rilogoruta.pdf
    • http://enterprisesbtc.com/uploads/1/3/0/4/130492229/divifanesojeje-zoxagufixovav.pdf
    • http://mrdombaza.com/uploads/1/3/0/6/130604524/xugunizak.pdf
    • http://glostixforkameron.com/uploads/1/3/0/7/130776478/wupiwugose.pdf
    • http://orthelackthereof.com/uploads/1/3/0/6/130621110/vejivabufemoz-komefivutu-rotabo-gagunuruvu.pdf
    • http://djgarbin.com/uploads/1/3/0/7/130740598/rurutivofokejito.pdf
    • http://spanishwithflor.org/uploads/1/3/0/5/130546040/jogududixe.pdf
    • http://936-mulching.com/uploads/1/3/0/7/130775607/6079562.pdf
    • http://bonjourlanguageservices.com/uploads/1/3/0/5/130550921/2197145.pdf
    • http://soltisoft.com/uploads/1/3/0/6/130604640/tabawujojo_gedugefutivuf_dojoxajan.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007e7d.bin
70d97b84b17da76b5fc4371fcbfe5416ef947d3e2443fd99c75f475324bba5b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E7D 7796 bytes
font_01_sfnt_off00009cef.bin
f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CEF 16204 bytes