Malicious PDF — malware analysis report

Static analysis result for SHA-256 20ce6dcd4b2c6465…

MALICIOUS

PDF

73.5 KB Created: 2021-03-15 09:00:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: 349e74425d93e46f0ae1fdec8669f78e SHA-1: a647b540f3182f748d021fb168e7d5be3b28b876 SHA-256: 20ce6dcd4b2c6465b5891720b0651d94ada5a5cef6d3cf832060b5a0feb1476d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which point to PDF files with numeric slugs, indicating a link farm or SEO spam tactic. The document body, though heavily obfuscated, contains text related to cleaning a carburetor, which is likely a lure to attract clicks to the malicious URLs. The presence of embedded URLs and the ML classifier's high confidence score further support the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/strik?utm_term=how+to+clean+a+carburetor+on+a+blower PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4421966/normal_600c0f909d390.pdfIn PDF document text
    • https://kufaxalerix.weebly.com/uploads/1/3/1/4/131453821/ratili_pogovore_xameweranobar_gaxijurorizotop.pdfIn PDF document text
    • https://cdn.sqhk.co/danajuva/iHOgceQ/sonny_bono_and_cher_marriage.pdfIn PDF document text
    • https://turetufifej.weebly.com/uploads/1/3/4/5/134500159/mesup.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4382405/normal_5fcd6c8fc64d7.pdfIn PDF document text
    • https://tirilume.weebly.com/uploads/1/3/4/8/134886795/puzodoxamamuxoripit.pdfIn PDF document text
    • https://cdn.sqhk.co/mewivupa/jjfVhjQ/35783981808.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4406516/normal_601bcfa5d1487.pdfIn PDF document text
    • https://cdn.sqhk.co/jozopotuwomo/gjijwha/tutibulisuwaguzenafuzul.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d5ce7d31-f5f1-45e9-88a4-580b1a96b97a/que_es_un_seminario_taller.pdfIn PDF document text
    • https://s3.amazonaws.com/nuruvapozixix/charlie_chaplin_2_bgm_music.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f5ad62f9-7dcc-4176-8063-f4be7f8588ff/vulozaxapibawibusugi.pdfIn PDF document text
    • https://s3.amazonaws.com/sepawi/jikumepatolemenutakizisix.pdfIn PDF document text
    • https://s3.amazonaws.com/mukutud/zimowopi.pdfIn PDF document text
    • https://s3.amazonaws.com/lezopobigeza/baixar_apk_facebook_messenger.pdfIn PDF document text
    • https://s3.amazonaws.com/nuxulikiwab/agos_ducato_numero_verde_informazioni.pdfIn PDF document text
    • https://s3.amazonaws.com/mixanaz/broken_heart_love_story_video_song.pdfIn PDF document text
    • https://s3.amazonaws.com/tibitexil/biology_matters_textbook_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/kudufigunabi/xopofamu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b875b726-90fc-4562-a585-9dad7720da22/6846699091.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/373cdeb1-2800-43af-905c-72b5b9515ed1/37287693338.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e5e3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE5E3 4808 bytes
SHA-256: c989c15303d27d5adc41d9fb5678d7ec990266ba672066e144f2a54f259ea4ca
font_01_sfnt_off0000f65c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF65C 10060 bytes
SHA-256: 82f6f8f0bd343f1625eec7882c61d81865110e08bd9c31c45e09efa1f255c6bf