Malicious PDF — malware analysis report

Static analysis result for SHA-256 3bf72a4653500e88…

MALICIOUS

PDF

36.8 KB Created: 2020-04-08 07:05:42 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 35608ddd7f9126897d8aa35a6cea954e SHA-1: 13682eb7cc72dfb7a7cee3b460624c49675d99b7 SHA-256: 3bf72a4653500e88a2b861f058e689fa2e98d7dbf151620a6bf0f034f0a12156
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to other PDF files hosted on various domains. This pattern is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thesecrettohealthyliving.com/uploads/1/3/0/2/130289482/130289482.html#asgard+assets+mass+effect+3
    • http://kravepixel.net/uploads/1/3/0/6/130621162/1098780.pdf
    • http://drpamelawoods.com/uploads/1/3/0/3/130379504/9f0547d0ade456.pdf
    • http://mywiguide.com/uploads/1/3/0/9/130969418/wuzularepinoz.pdf
    • http://mexicovirreinal.com/uploads/1/3/0/5/130544878/gidadogok-totufep-rilobopidekol.pdf
    • http://rocklineclothing.com/uploads/1/3/0/5/130543059/kokizajanubo.pdf
    • http://dragondrones.org/uploads/1/3/0/5/130542692/latezewotidubibexo.pdf
    • http://embodiedentertainment.com/uploads/1/3/0/5/130547812/japakegep-lanudurokan.pdf
    • http://centerofspirituallight.org/uploads/1/3/0/6/130621407/7601073.pdf
    • http://divinacosmos.com/uploads/1/3/0/4/130483869/venolisupob.pdf
    • http://waxxbrothers.com/uploads/1/3/0/2/130272848/ruzuximiramadem-rimidegini-wugezalu.pdf
    • http://tryonsquare.com/uploads/1/3/0/4/130477090/445770.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006612.bin
03b1d575d5aae6c2d4931225e37080070e1e4d1885333346964da47361d7ee7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6612 7952 bytes