Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f57563982663142…

MALICIOUS

PDF

33.1 KB Created: 2020-04-09 23:15:58 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: af91ec5557eb817228fc7d626523d223 SHA-1: e8691b396e57a1f7d34bc532f9d3a68f600ae2fe SHA-256: 2f5756398266314249691e1bc4521d7c79e2aa9ec6ff01450e93013273d8232c
172 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, many of which are structured to appear as SEO-optimized content, suggesting a link farm or phishing lure. The heuristic 'PDF_SUSPICIOUS_LINK_LURE' specifically indicates an invisible link to a suspicious domain, 'server-secure-portal9.online'. The ML classifier strongly flagged this PDF as malicious. No scripts were extracted, but the extensive linking and evasion techniques point towards a delivery mechanism for malicious content hosted on external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://geekygreengirl.com/uploads/1/3/1/3/131398235/131398235.html#pokemon+zeta+and+omicron+speed+up
    • http://foreverychildren.org/uploads/1/3/1/4/131437465/nusutobu-tobofu-xemafopus.pdf
    • http://newhavenclients.com/uploads/1/3/0/7/130739916/moworuli.pdf
    • http://brandonjayfoster.com/uploads/1/3/0/7/130775116/2179786.pdf
    • http://hillspoolservices.com/uploads/1/3/0/4/130476152/f18df.pdf
    • http://god-almighty.com/uploads/1/3/0/6/130640142/d86c8a.pdf
    • http://mtgileadbaptistchurch.com/uploads/1/3/0/4/130489143/fefc0f093e9c998.pdf
    • http://kingdombedding.com/uploads/1/3/0/6/130603948/xolubibuvopepam.pdf
    • http://rubbercityshakes.com/uploads/1/3/0/6/130620880/xeladoxaru.pdf
    • http://tanju.nyc/uploads/1/3/0/8/130814805/metunazuxereduv.pdf
    • http://tripgent.com/uploads/1/3/0/5/130551386/bolalujefaja.pdf
    • http://server-secure-portal9.online/uploads/1/3/1/4/131437925/tukemavidisulat.pdf
    • http://mynewdomainlive.com/uploads/1/3/0/4/130488357/zedusig_wurav_sirob_woxesoxekowoxom.pdf
    • http://escapekewanee.com/uploads/1/3/1/3/131384306/d39a91ee61f4e.pdf
    • http://michelleberceau.com/uploads/1/3/1/4/131406945/mimivazutuzof.pdf
    • http://katieamandamyers.com/uploads/1/3/0/8/130814774/donutomapumox_xowulelub_wevov_nuwabe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005912.bin
1a1a11750020d031d8a908bb43bb71d4873eb11de6543f58f6c4b639f41cddfd
pdf-font-stream PDF embedded font (sfnt) at offset 0x5912 7936 bytes