Malicious PDF — malware analysis report

Static analysis result for SHA-256 20c72d243a33c87e…

MALICIOUS

PDF

62.4 KB Created: 2020-04-02 05:52:43 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 0d3f6e392a0b1202b28db7ac7fecb7e6 SHA-1: 7a53dbe27804898fe3a526daf8284953529d2edb SHA-256: 20c72d243a33c87e4163640f5fe998c23c81cd4615f53edd8049e39499674dd6
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, a technique commonly used for SEO manipulation or to distribute further malicious content. The ML classifier strongly indicated maliciousness. The embedded links point to various PDF files hosted on unrelated domains, suggesting a coordinated effort to spread content or traffic.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://prosurfaceinstall.com/uploads/1/3/1/3/131383753/131383753.html#ecuacion+de+estado+gas+de+van+der+waals
    • http://rodshoptees.com/uploads/1/3/0/8/130813521/4821b.pdf
    • http://nowpixapp.com/uploads/1/3/0/7/130738854/petazu-sovekuma-kavinijujubuxu.pdf
    • http://mrsparsons.net/uploads/1/3/1/4/131438539/lozefex.pdf
    • http://rollingdoorrepairny.com/uploads/1/3/0/8/130813896/6465967.pdf
    • http://zoliandrico.com/uploads/1/3/0/4/130476146/021276fc1e80.pdf
    • http://pittsburghlasertattooremoval.com/uploads/1/3/0/2/130289393/bebin-boruv.pdf
    • http://threehillsagritourism.com/uploads/1/3/0/7/130739491/5251044.pdf
    • http://cartermountainphoto.com/uploads/1/3/0/7/130775380/8c7c06.pdf
    • http://homesofhopenepal.com/uploads/1/3/0/9/130969659/b0fcaa.pdf
    • http://hinnerschietzinsurance.com/uploads/1/3/0/2/130270832/54ba1.pdf
    • http://bitcoincomichandbook.com/uploads/1/3/1/1/131164257/fibov-supiz-bupefig-kufax.pdf
    • http://beachmutt.net/uploads/1/3/0/5/130551556/sekizesabumi_nadimabop_rufokirifukelus_vedufiboxeti.pdf
    • http://besthomeimprovementsusa.com/uploads/1/3/0/5/130540507/kupot_lugupep_weziwo_ledimabobukini.pdf
    • http://powertojustice.com/uploads/1/3/0/7/130776386/4e3516c14cd17.pdf
    • http://mindset-hypno.com/uploads/1/3/0/5/130588487/2063000.pdf
    • http://poprepa.ie/uploads/1/3/0/4/130435725/630594.pdf
    • http://www.beejoyfulsoap.com/uploads/1/3/0/6/130621524/578d26e70a40c.pdf
    • http://morganmcbrooks.com/uploads/1/3/1/3/131383977/a6ccf1ecd8d90.pdf
    • http://rbilivingwell.com/uploads/1/3/0/2/130270985/e4eb45d45ac7cc4.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a564.bin
da70d5eb554872996a5ab6e3bf688c67b7b57035dd34e7f0574a453039f56e34
pdf-font-stream PDF embedded font (sfnt) at offset 0xA564 9052 bytes
font_01_sfnt_off0000c6b0.bin
5b3a079f0a50d4137c8589a3730218802c98c163897a7e51d77e9b8498d422ed
pdf-font-stream PDF embedded font (sfnt) at offset 0xC6B0 4032 bytes
font_02_sfnt_off0000d491.bin
d3b89afe1ce40f5ef4f3216c30546a154707953a74b7d4b7811f10aa17b1a9d5
pdf-font-stream PDF embedded font (sfnt) at offset 0xD491 16108 bytes