Malicious PDF — malware analysis report

Static analysis result for SHA-256 12998952b56b07b3…

MALICIOUS

PDF

40.9 KB Created: 2020-05-22 22:49:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d11db1535957e3b818990990ffdd33b5 SHA-1: f190e03609d9bb5ea5306615b4c3c0a8dc4cd291 SHA-256: 12998952b56b07b3a9426d60eeb7caba5005f103a4b136d7fd06de187635586b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains a large number of embedded external URLs, indicating a likely attempt to manipulate search engine results or redirect users to malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent. No scripts were extracted, and the document body is heavily obfuscated, preventing a more detailed analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thenorafarms.com/uploads/1/3/0/7/130739775/130739775.html#baixar+livro+marlene+mukai
    • http://naugatuckchamber.biz/uploads/1/3/0/2/130287883/tefapaf.pdf
    • http://arafoods.net/uploads/1/3/0/7/130776185/nuparawomo-vajis.pdf
    • http://whatisgreshamslaw.com/uploads/1/3/0/9/130969598/7760843.pdf
    • http://triplegbuildconstruct.com/uploads/1/3/1/4/131437622/b71706ee.pdf
    • http://eleven-ideas.com/uploads/1/3/0/4/130435821/medudi.pdf
    • http://azbaseballacademy.com/uploads/1/3/0/5/130590322/zuwopokavoti.pdf
    • http://ssm-salekhard.ru/uploads/1/3/0/5/130590169/d63db57b813.pdf
    • http://ohmyworldtours.com/uploads/1/3/1/1/131164471/7583739.pdf
    • http://compositemethods.com/uploads/1/3/0/4/130477293/xodimujudel_tuxites_tigazifubi_vutub.pdf
    • http://centenorodriguez.com/uploads/1/3/1/4/131482944/7612360.pdf
    • http://thewoodlandstax.net/uploads/1/3/0/8/130814104/69ad16518e7a1.pdf
    • http://preschoolkaty.com/uploads/1/3/0/6/130639183/kuzokipikomuveg-kajogekusareg-welevi.pdf
    • http://starpestcontrolpr.com/uploads/1/3/1/4/131452836/xakewuxugi.pdf
    • http://afcyberworx.info/uploads/1/3/0/3/130313786/barajomiga-wogurilul.pdf
    • http://malolokids.com/uploads/1/3/0/8/130874629/8982426.pdf
    • http://doodledesignsandrhymes.com/uploads/1/3/0/5/130551086/1b3804cbe60882.pdf
    • http://wecareservice.net/uploads/1/3/1/6/131636988/efe630.pdf
    • http://awesomenoun.com/uploads/1/3/0/7/130776370/laliwoponat.pdf
    • http://madewithlovebydanielle.com/uploads/1/3/0/6/130639641/7499676.pdf
    • http://themoonladder.com/uploads/1/3/0/8/130874410/a6a91.pdf
    • http://sundayimpression.com/uploads/1/3/0/5/130589033/pugeposewazugipelad.pdf
    • http://rightlinc.org/uploads/1/3/0/8/130874680/6375016.pdf
    • http://gpcglobalproductcertification.com/uploads/1/3/0/9/130968972/jozodoreremov.pdf
    • http://yourchinaguy.com/uploads/1/3/0/8/130814157/bipibolovusodowufuw.pdf
    • http://peacockchildcare.com/uploads/1/3/0/5/130546354/9184680.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000071bc.bin
17c6bda12ba4146c685c363a765390a91567877018acea9d7f8daf7c7cc6aaf4
pdf-font-stream PDF embedded font (sfnt) at offset 0x71BC 12152 bytes