Malicious PDF — malware analysis report

Static analysis result for SHA-256 139e94ae4e61ccd6…

MALICIOUS

PDF

31.7 KB Created: 2020-06-17 18:55:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2020-09-24
MD5: 34fef8d5ee37ad1e464c23c1d09ebfd7 SHA-1: 5b18719773fb5a8e3e414699640c80659fe915a2 SHA-256: 139e94ae4e61ccd6843656a12678009eb88a843f9408c42bd796276e0b4ea7bd
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file is identified as malicious due to its structure, which resembles a screenshot lure designed to trick users into clicking embedded links. The document body contains numerous URLs, indicating a link farm strategy. The primary attack pattern involves directing users to external websites, likely for phishing or further malware distribution, leveraging the 'Spearphishing Attachment' technique. Although no scripts were directly extracted, the presence of embedded URIs suggests potential for JavaScript execution or redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 31 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://legendarypearls.net/uploads/1/3/0/6/130605018/130605018.html#children+literature+pdf PDF link annotation
    • http://wmjcommunitydevelopment.net/uploads/1/3/1/1/131164431/f643da755b711c.pdfIn PDF document text
    • http://propertymanagementproblems.com/uploads/1/3/0/5/130590180/junovezewizejip-kexojup-bimesexojaxi.pdfIn PDF document text
    • http://foreverstartingnow.com/uploads/1/3/1/4/131453934/2508014.pdfIn PDF document text
    • http://dynacureusa.com/uploads/1/3/0/5/130589080/607d96ea6f79255.pdfIn PDF document text
    • http://mta-sts.marksmithillustration.com/uploads/1/3/1/3/131380977/aebef.pdfIn PDF document text
    • http://wellnessreclamation.com/uploads/1/3/1/8/131871614/vawabagaxamaje.pdfIn PDF document text
    • http://mail.edulisdesigns.com/uploads/1/3/0/7/130776308/dovaxu-bexotunozote-salisusodon.pdfIn PDF document text
    • http://blossom.ch/uploads/1/3/0/9/130969212/7054659.pdfIn PDF document text
    • http://leaderwithpurpose.com/uploads/1/3/0/5/130590353/jawonixilivatewoj.pdfIn PDF document text
    • http://appllancepro.com/uploads/1/3/0/7/130738662/mabefaruxagigasakaso.pdfIn PDF document text
    • http://webmail.grinandgrowchildcare.org/uploads/1/3/1/4/131438474/wubefifinudagivonur.pdfIn PDF document text
    • http://ruyabankasi.com/uploads/1/3/0/7/130776661/a45b0f.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000047c1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x47C1 4744 bytes
SHA-256: 6211e1746bd4d499c3c824197768676a1f420d245305611f2f79d47cadedac97
font_01_sfnt_off000057cc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x57CC 7944 bytes
SHA-256: 8423224c5ea8854cb5650275e020ac559a8d6f4312388553e214823529cfea8c