Malicious PDF — malware analysis report

Static analysis result for SHA-256 139e94ae4e61ccd6…

MALICIOUS

PDF

31.7 KB Created: 2020-06-17 18:55:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 34fef8d5ee37ad1e464c23c1d09ebfd7 SHA-1: 5b18719773fb5a8e3e414699640c80659fe915a2 SHA-256: 139e94ae4e61ccd6843656a12678009eb88a843f9408c42bd796276e0b4ea7bd
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file is identified as malicious due to its structure, which resembles a screenshot lure designed to trick users into clicking embedded links. The document body contains numerous URLs, indicating a link farm strategy. The primary attack pattern involves directing users to external websites, likely for phishing or further malware distribution, leveraging the 'Spearphishing Attachment' technique. Although no scripts were directly extracted, the presence of embedded URIs suggests potential for JavaScript execution or redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 31 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://legendarypearls.net/uploads/1/3/0/6/130605018/130605018.html#children+literature+pdf
    • http://wmjcommunitydevelopment.net/uploads/1/3/1/1/131164431/f643da755b711c.pdf
    • http://propertymanagementproblems.com/uploads/1/3/0/5/130590180/junovezewizejip-kexojup-bimesexojaxi.pdf
    • http://foreverstartingnow.com/uploads/1/3/1/4/131453934/2508014.pdf
    • http://dynacureusa.com/uploads/1/3/0/5/130589080/607d96ea6f79255.pdf
    • http://mta-sts.marksmithillustration.com/uploads/1/3/1/3/131380977/aebef.pdf
    • http://wellnessreclamation.com/uploads/1/3/1/8/131871614/vawabagaxamaje.pdf
    • http://mail.edulisdesigns.com/uploads/1/3/0/7/130776308/dovaxu-bexotunozote-salisusodon.pdf
    • http://blossom.ch/uploads/1/3/0/9/130969212/7054659.pdf
    • http://leaderwithpurpose.com/uploads/1/3/0/5/130590353/jawonixilivatewoj.pdf
    • http://appllancepro.com/uploads/1/3/0/7/130738662/mabefaruxagigasakaso.pdf
    • http://webmail.grinandgrowchildcare.org/uploads/1/3/1/4/131438474/wubefifinudagivonur.pdf
    • http://ruyabankasi.com/uploads/1/3/0/7/130776661/a45b0f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000047c1.bin
6211e1746bd4d499c3c824197768676a1f420d245305611f2f79d47cadedac97
pdf-font-stream PDF embedded font (sfnt) at offset 0x47C1 4744 bytes
font_01_sfnt_off000057cc.bin
8423224c5ea8854cb5650275e020ac559a8d6f4312388553e214823529cfea8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x57CC 7944 bytes