Malicious PDF — malware analysis report

Static analysis result for SHA-256 3fe852c8f09b793b…

MALICIOUS

PDF

44.2 KB Created: 2020-03-09 11:20:13 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: e7a9faaca27e71279155ad0976464fca SHA-1: 7e266153546eff912a3b94c8a200a2c55c42377c SHA-256: 3fe852c8f09b793bb231295e7d49cbb05be6854db453b192b8093d8d53360191
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links to external PDF files hosted on various domains. This technique is often used for SEO spam or to distribute further malicious content. The ML classifier strongly flagged this PDF as malicious, and the presence of a link farm heuristic further supports this assessment. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cpanel.gammaxiques.org/uploads/1/3/0/6/130604993/130604993.html#unique+facts+about+sickle+cell+anemia
    • http://itpillows.com/uploads/1/3/0/5/130588907/toxunonizebu-godomide.pdf
    • http://life.ashleymartinportfolio.com/uploads/1/3/0/6/130640049/74ad8c025cbfdaf.pdf
    • http://www.lawrencepestpros.com/uploads/1/3/0/7/130775832/9286198.pdf
    • http://jaylappin.com/uploads/1/3/0/2/130272586/481771.pdf
    • http://www.pasttense-massage.com/uploads/1/3/0/7/130776525/kivexiwugul.pdf
    • http://dogwalkersvancouver.co/uploads/1/3/0/3/130379231/wobemiz.pdf
    • http://ma-engrs.net/uploads/1/3/0/6/130620835/kamemowig.pdf
    • http://www.partynm.com/uploads/1/3/0/8/130814190/974776.pdf
    • http://shopnightout.com/uploads/1/3/0/7/130738955/bugapuvig.pdf
    • http://outpostprinting.com/uploads/1/3/0/6/130604869/senakasel-gavanosusanu-gezevebuwof-vikowatu.pdf
    • http://jordankuzmanovski.com/uploads/1/3/0/4/130477448/15aceb5797b6c.pdf
    • http://mwwrenovations.com/uploads/1/3/0/6/130604104/soziweroteze.pdf
    • http://kitchengator.com/uploads/1/3/0/4/130483769/lanosa.pdf
    • http://msdsminesitedieselservices.com/uploads/1/3/0/6/130640088/naraxiji.pdf
    • http://vclpaintingllc.com/uploads/1/3/0/9/130969391/rakepezud.pdf
    • http://digitalmediamarketingservice.com/uploads/1/3/0/4/130483325/garalomereme.pdf
    • http://jesusknows.org/uploads/1/3/0/8/130873961/1572782.pdf
    • http://yourwellnessbranch.com/uploads/1/3/0/3/130379488/nolejedo_podupiketenoko.pdf
    • http://northchannelnetwork.org/uploads/1/3/0/4/130483385/1dfe5b.pdf
    • http://nextdeavor.net/uploads/1/3/0/6/130621871/lixokixolabonole.pdf
    • http://kcshore.com/uploads/1/3/0/3/130379326/jovuxamekafuzevolin.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000083ff.bin
513fa90be298d6077ea8244c8c25ff5177870f816c942a8bdc169b69a56dddb0
pdf-font-stream PDF embedded font (sfnt) at offset 0x83FF 7632 bytes