Malicious PDF — malware analysis report

Static analysis result for SHA-256 28b7959cd67b48bb…

MALICIOUS

PDF

51.4 KB Created: 2020-06-11 16:02:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 32aaf9cf9c7d511ed2da357f74b1f523 SHA-1: 4d47b531436d8b27047c7485b03dda24895212bd SHA-256: 28b7959cd67b48bbca9e5942302da0dcda4d5addfc34936d4978fa01eb6e0e8f
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which are dynamically generated and point to PDF files, characteristic of a link farm or SEO spam. One of the primary links, 'http://johnmajoris.com/uploads/1/3/0/5/130551654/130551654.html#pdf+to+word+online', suggests a lure for users seeking online document conversion tools. The ML classifier strongly indicated maliciousness, supporting the interpretation that these links are intended for malicious purposes, such as phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://johnmajoris.com/uploads/1/3/0/5/130551654/130551654.html#pdf+to+word+online
    • http://canaanchristianministries.com/uploads/1/3/1/8/131871910/muwovitabekeb_ruwoxa_xapemutaponi.pdf
    • http://thorneandivy.com/uploads/1/3/1/3/131382239/zeveto-jeginogeliw-dibipi-bakazogogez.pdf
    • http://vituldesignz.shop/uploads/1/3/1/8/131857120/sunogav-xodokojav.pdf
    • http://thenodramamamas.com/uploads/1/3/0/2/130289254/1f3df6fc062359d.pdf
    • http://raising-greens.com/uploads/1/3/1/3/131383441/1690517.pdf
    • http://brendanchapman.com/uploads/1/3/1/3/131398174/xivapob_jefizedaxi_jakapaz_birawu.pdf
    • http://blueheronscientific.com/uploads/1/3/0/8/130873758/724cd5c4c466be5.pdf
    • http://j-elberfeld.com/uploads/1/3/0/8/130874620/bezotoriwekob.pdf
    • http://midwestundergroundinc.com/uploads/1/3/0/2/130289291/padaf.pdf
    • http://leahjoyandsaintpatrick.com/uploads/1/3/0/2/130270781/5753994.pdf
    • http://marthamckaydesign.com/uploads/1/3/0/9/130969623/jakesusofutole.pdf
    • http://enbit.com.au/uploads/1/3/1/4/131483068/gopabokipi_lapojidefoxu.pdf
    • https://mikupekuforu902814454.files.wordpress.com/2020/06/vubenizofiwafeboxo.pdf
    • https://tesodufow.files.wordpress.com/2020/06/19224870227.pdf
    • https://rufofuvokije.files.wordpress.com/2020/06/96073713689.pdf
    • https://jizogozup.files.wordpress.com/2020/06/92763556256.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007903.bin
91838cdcd5e0aafc5bf0af0349e66d06387e1551d24a013491c16510681f740e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7903 6424 bytes
font_01_sfnt_off000088e1.bin
7927332039f2d6124006e512d1b4951d9de5d95cfcfccb5f4b52ccf945982afd
pdf-font-stream PDF embedded font (sfnt) at offset 0x88E1 10376 bytes
font_02_sfnt_off0000acb3.bin
f0a8b786da721c7415a59d91fbce3b20bbb98ea32e48857ac1ff22d53b00ec29
pdf-font-stream PDF embedded font (sfnt) at offset 0xACB3 16144 bytes