Malicious PDF — malware analysis report

Static analysis result for SHA-256 177a273aa22bbe2b…

MALICIOUS

PDF

91.4 KB Created: 2020-03-21 19:22:36 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d3f5f10da2a7b6cf24d04b153265a8e5 SHA-1: 7478f39684ebd27017c106ccd5b5073f39ca904c SHA-256: 177a273aa22bbe2b70cd668bcee2787086b2eda94292995e7dc4c9eb26fa061d
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are dynamically generated or follow a pattern indicative of a link farm or SEO spam. The heuristic 'PDF_SEO_LINK_FARM' and the presence of numerous unknown-reputation URLs strongly suggest this document is designed to redirect users to malicious websites or facilitate the download of further malware. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://exceptional-body-language.com/uploads/1/3/0/2/130291575/130291575.html#que+es+webct+y+para+que+sirve
    • http://s-w-p.org/uploads/1/3/0/4/130435751/6d85ac310b5.pdf
    • http://lb199x.com/uploads/1/3/0/4/130476493/353097.pdf
    • http://pisgahit.com/uploads/1/3/0/4/130436494/7991128.pdf
    • http://www.k2swag.com/uploads/1/3/0/6/130640047/87fe64c.pdf
    • http://www.offbeat-apothecary.com/uploads/1/3/0/7/130739928/bowinil_genesozix_gopiboki_tojewif.pdf
    • http://www.technidyneasia.com/uploads/1/3/0/3/130379137/fujavumimo-nolapopaj.pdf
    • http://whywasteworld.com/uploads/1/3/0/6/130620484/xelagisime_totabar.pdf
    • http://vegansafaris.com/uploads/1/3/0/2/130271067/8130210.pdf
    • http://proudpapagear.com/uploads/1/3/0/5/130590233/1192609.pdf
    • http://chironetics.com/uploads/1/3/0/5/130550667/nozefas.pdf
    • http://bioenergija.info/uploads/1/3/0/7/130739280/zevopili.pdf
    • http://snappornity.com/uploads/1/3/0/5/130543467/lejubajimerup.pdf
    • http://mywonderowl.com/uploads/1/3/0/3/130379398/1723920.pdf
    • http://www.mrandmrslynch.net/uploads/1/3/0/6/130605212/4569242.pdf
    • http://www.revsurfco.com/uploads/1/3/0/7/130775997/tilizo-lirinuveropi-rudizubofet-zoguwosujo.pdf
    • http://itemhustle.com/uploads/1/3/0/5/130588220/6398433.pdf
    • http://p�veggen.no/uploads/1/3/1/0/131070940/7619795.pdf
    • http://citywidevalet.com/uploads/1/3/0/4/130476203/9688342.pdf
    • http://www.cheapceramicknives.com/uploads/1/3/0/6/130604433/4ab6d83f36d07.pdf
    • http://basismarkt.com/uploads/1/3/0/7/130739742/88d9358b490e1b7.pdf
    • http://brownwoodhealthdepartment.com/uploads/1/3/0/6/130603838/7376983.pdf
    • http://xn--pveggen-exa.no/uploads/1/3/1/0/131070940/7619795.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011601.bin
b6891aa7786c0f618d7720300f3a5dc3ec2eafd42dc23a95255b0b8dea98b18f
pdf-font-stream PDF embedded font (sfnt) at offset 0x11601 11796 bytes
font_01_sfnt_off00013db5.bin
fe99f3cf5c22032b6a205105c04cca758faff213b63c29db5e8c872fe081e876
pdf-font-stream PDF embedded font (sfnt) at offset 0x13DB5 2680 bytes
font_02_sfnt_off00014744.bin
a9ac656c207fea9a83458f10ebabe76f4863d1266846e5e298c3cf9f489939fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x14744 16264 bytes