Malicious PDF — malware analysis report

Static analysis result for SHA-256 11393e69d33e8c3d…

MALICIOUS

PDF

41.1 KB Created: 2020-04-08 10:28:17 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: eb138042f237233a0a1e74a46147debb SHA-1: 0a364758f91322f1ca8c179575e7b85baf2393a8 SHA-256: 11393e69d33e8c3d85b03a7324aa37e263d60c5f75e42d51bf33f94007129b23
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files on different domains. The ML classifier also strongly indicated maliciousness. While no scripts were extracted, the presence of numerous external links suggests an attempt to redirect the user to potentially malicious content or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://convergeclub.com/uploads/1/3/0/4/130490444/130490444.html#salud+publica+estados+unidos
    • http://goldenapplesect.org/uploads/1/3/1/4/131437194/aed2d3.pdf
    • http://drisenproducts.com/uploads/1/3/0/5/130544938/todutuvuwisobisezo.pdf
    • http://robiskincare.ca/uploads/1/3/0/3/130323417/af765.pdf
    • http://shishkebobscafe.com/uploads/1/3/1/4/131406966/gojojomebobogewut.pdf
    • http://kingstonclockrepair.com/uploads/1/3/0/7/130775567/wiketujama_gijifexoxa_vowedibudaki.pdf
    • http://villagecarehenfield.co.uk/uploads/1/3/0/5/130588546/vukubipopikijowizure.pdf
    • http://jrgenua.ca/uploads/1/3/0/6/130621223/wedivu.pdf
    • http://outtasightstorage.net/uploads/1/3/1/4/131452950/muxikituw-sejemonon-jijevuwatiki.pdf
    • http://thehilltopbarn.com/uploads/1/3/0/5/130551166/soralufukife_litazavolis_rojuzudora.pdf
    • http://kenplattlaw.net/uploads/1/3/1/4/131406600/fovojipikijata-kezinowabol.pdf
    • http://lakewoodinvestments.ca/uploads/1/3/0/5/130551477/8946951.pdf
    • http://lashego.com/uploads/1/3/0/2/130289185/gonuvameremejirisiri.pdf
    • http://myrmidonentertainment.com/uploads/1/3/1/4/131438759/menugipu-xuruxuwelen-wixokarimagamu.pdf
    • http://adsl-63-204-18-43.benefitplans.org/uploads/1/3/0/5/130546880/zuposuwakisomip.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000075a2.bin
ba82a53e479971e92b93ceeef607c11fd9edfdd96eccc0cb83b0d5e6c81df7e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x75A2 9072 bytes