Malicious PDF — malware analysis report

Static analysis result for SHA-256 14cd1a8123c124ab…

MALICIOUS

PDF

42.7 KB Created: 2020-03-12 13:22:28 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 92ea256104f8247cee8db1f57f12983d SHA-1: f5ec439faface0f0634a2a211d0eb465a9c5aa2f SHA-256: 14cd1a8123c124ab2727905e036726e21a3e12d7a1f306144166f73d7ef78add
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

This PDF file exhibits characteristics of a link farm, embedding a large number of external URLs. The primary heuristic indicates a mass of external PDF links, suggesting an attempt to manipulate search engine results or redirect users to potentially malicious content. No scripts were extracted, and the document body is heavily obfuscated, making it difficult to determine a more specific attack pattern beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.geobiologiabarcelona.es/uploads/1/3/0/2/130272963/130272963.html#passive+voice+structure+chart
    • http://74-123-78-11.mgwnet.com/uploads/1/3/0/5/130539115/fegenivupo_favelawaseputi_zorak_kirumidoro.pdf
    • http://blanchardstevens.com/uploads/1/3/0/6/130621200/4124685.pdf
    • http://missamericanfork.com/uploads/1/3/0/6/130620752/6623141.pdf
    • http://www.abbepsychservices.com/uploads/1/3/0/3/130379098/mubawipem.pdf
    • http://specializedfit.com/uploads/1/3/0/7/130776602/magoxud-nivopibiket-zobobezosefadik-larowezojagaluv.pdf
    • http://thepeanutpatrol.org/uploads/1/3/0/4/130435581/xugada_lifevew_napamukurire.pdf
    • http://vancouverislandpremiumhardcandy.com/uploads/1/3/0/3/130379145/wodivipipoxixat.pdf
    • http://morristem.com/uploads/1/3/0/7/130776123/c17c8.pdf
    • http://techsortie.com/uploads/1/3/0/3/130313161/0299b2167365b8b.pdf
    • http://everydayolympian.com/uploads/1/3/0/6/130639552/e4f261988fb.pdf
    • http://www.chordofappeals.com/uploads/1/3/0/7/130775472/459933f46d.pdf
    • http://www.eyconsultancy.com/uploads/1/3/0/7/130739318/fivologedad.pdf
    • http://www.ktmflooringandmore.com/uploads/1/3/0/6/130639304/tuserokugenus.pdf
    • http://www.nomoneynohoney.online/uploads/1/3/0/7/130775543/47f459299f52.pdf
    • http://drumnerd.com/uploads/1/3/0/6/130605113/batavejos_rudamidowepulo_pozij_zupiru.pdf
    • http://acadiacannabis.com/uploads/1/3/0/4/130488543/1b1f20c5786762.pdf
    • http://www.lowertokenburyequestriancentre.com/uploads/1/3/0/6/130605059/9886420.pdf
    • http://thedoulamom.com/uploads/1/3/0/2/130289550/05ef0895432.pdf
    • http://starcustomsgr.com/uploads/1/3/0/7/130774993/borifepobulo_rovonogu_mawuwuginifow_gajolugodab.pdf
    • http://sshvug.com/uploads/1/3/0/6/130603682/wubivemotomenabuwe.pdf
    • http://stacysdogtraining.com/uploads/1/3/0/4/130483491/558fa986c7b2459.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000746e.bin
9c6f13fbbb0dfe90c8661039de09335c4b84beca6a72a9a09f5aaecf7cb1d93e
pdf-font-stream PDF embedded font (sfnt) at offset 0x746E 8008 bytes
font_01_sfnt_off000093ae.bin
e2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea
pdf-font-stream PDF embedded font (sfnt) at offset 0x93AE 2652 bytes