Malicious PDF — malware analysis report

Static analysis result for SHA-256 1236e324d8b724eb…

MALICIOUS

PDF

40.8 KB Created: 2020-05-22 10:48:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3ef92d75e718f55fd3f96156b4511eee SHA-1: 4f49875c4053413730b54e923910fa6b5c4bf638 SHA-256: 1236e324d8b724ebcbb65b041c9c24088e572eb1a21cfd7263c04b6bb1d61634
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The embedded document body text also contains a prominent URL, suggesting the primary purpose is to redirect users to a network of linked content. No scripts were extracted, but the extensive linking pattern indicates a likely SEO spam or content distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://slimetym.com/uploads/1/3/0/4/130489803/130489803.html#cosmic+catch+instructions
    • http://ivan-molloy.com/uploads/1/3/0/4/130483457/47456ce6d.pdf
    • http://treeserviceallen.net/uploads/1/3/0/5/130551015/tofolonirovaxupit.pdf
    • http://alphamaxtax.com/uploads/1/3/0/5/130550681/mifufuzopame.pdf
    • http://elevatedlife.me/uploads/1/3/1/3/131379296/2412565.pdf
    • http://cutbows.com/uploads/1/3/0/2/130273743/kefexizep.pdf
    • http://ripplevfx.com/uploads/1/3/1/8/131856224/lajinofubuda.pdf
    • http://fiftyfive11.com/uploads/1/3/1/1/131164016/nolegarujemulirefopa.pdf
    • http://floatllc.net/uploads/1/3/0/7/130740213/c54c79.pdf
    • http://politics4all.com/uploads/1/3/0/2/130272928/sasawove-zewevu-fuzonadetusi.pdf
    • http://adelightllc.com/uploads/1/3/0/6/130621436/lumatujupubituxanoma.pdf
    • http://thebodyclinic.services/uploads/1/3/1/3/131398174/9430264.pdf
    • http://nowtrainer.com/uploads/1/3/0/3/130313567/maxikilisew-dugasig-fekonozuvesiwik.pdf
    • http://dentonpestpros.com/uploads/1/3/1/3/131383790/vaxitoxuj_xogofunusurazoz_duraluremug.pdf
    • http://elfannapolis.com/uploads/1/3/1/6/131606094/9697221.pdf
    • http://robertcvitkovic.com/uploads/1/3/0/6/130639313/wewozugejul.pdf
    • http://sunands.com/uploads/1/3/0/6/130640078/zeniwadagudama-kozawi-konofagun-mogexared.pdf
    • http://bluewaternrhs.org/uploads/1/3/0/7/130739778/6328039.pdf
    • http://foxprofessionals.org/uploads/1/3/0/2/130287896/xivozuwanitego.pdf
    • http://architecturallandmarksus.com/uploads/1/3/0/7/130775805/buzojedonexi.pdf
    • http://pghchiro.com/uploads/1/3/0/9/130969865/bac864aec573f62.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000071f4.bin
4664845210ff22a4a1b11095013b95710d76b1999887df25373b4526efe8dc21
pdf-font-stream PDF embedded font (sfnt) at offset 0x71F4 11120 bytes