Malicious PDF — malware analysis report

Static analysis result for SHA-256 33e7cd16087e38f8…

MALICIOUS

PDF

55.8 KB Created: 2020-03-22 13:10:09 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 4d962bcfae8f8f752851ec16ec9d5f1a SHA-1: 2a1ff9b423866667e4d2e59f2083fd3f79cf3d71 SHA-256: 33e7cd16087e38f80b7dc17ab956931e8df297525f6db6727d5d8426822e398f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many with numeric slugs, indicative of a link farm or SEO manipulation tactic. The embedded document body text, while garbled, contains a URL that is also present in the heuristics and the list of URLs. This suggests the PDF's primary purpose is to redirect users to external websites, potentially for malicious purposes such as hosting further exploits or phishing content. No scripts were extracted, limiting the analysis of direct execution capabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dylanwyke.com/uploads/1/3/0/5/130588560/130588560.html#rig+veda+in+hindi+online+read
    • http://risesportscast.com/uploads/1/3/0/7/130776801/goxidemifejuraliwura.pdf
    • http://www.50plussguiden.no/uploads/1/3/0/9/130969260/1062324.pdf
    • http://rensselaervilleramble.org/uploads/1/3/0/7/130776180/7939679.pdf
    • http://littlehousefoodsocal.com/uploads/1/3/0/5/130588551/jubabiviterove-vonabi-sorinurawasago-feveguvajap.pdf
    • http://brandonkew.com/uploads/1/3/0/6/130639929/66804.pdf
    • http://kerrymckenna.com/uploads/1/3/0/4/130475959/c95b6a85.pdf
    • http://caterers.solutions/uploads/1/3/0/4/130490399/7933525.pdf
    • http://planningprotocol2.com/uploads/1/3/0/4/130435701/lololasikevepin.pdf
    • http://rootsbeforereach.com/uploads/1/3/0/6/130604518/sitonexuw.pdf
    • http://www.soultrainchoir.co.uk/uploads/1/3/0/5/130540664/873a0e9128f2.pdf
    • http://thesockingdead.com/uploads/1/3/0/6/130603741/fc60d818e.pdf
    • http://fedorahosted.org/lohit
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007d92.bin
7ac74365f35e54c3326b3c672ad828c2c36ab3f9b91fa3f16f5d390b5bc2c567
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D92 7948 bytes
font_01_sfnt_off00009c57.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C57 1388 bytes
font_02_sfnt_off0000a3bd.bin
45ba83ea3a71cb824ecba25d9a2c12c4ccc15a9cbc54238a18d3287b52302629
pdf-font-stream PDF embedded font (sfnt) at offset 0xA3BD 15424 bytes