Malicious PDF — malware analysis report

Static analysis result for SHA-256 4070303e59339728…

MALICIOUS

PDF

62.4 KB Created: 2020-04-01 17:53:29 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 33e038b17caa4c6c4c2748df05b052be SHA-1: 7fccc5446e27ba6557ab69202b44332749535ded SHA-256: 4070303e593397288f0a8cf1c773772ce3a79edeb65469566e93c21928747fc2
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, many of which point to similarly structured URLs on different domains. This pattern is indicative of a link farm or a phishing campaign designed to distribute malicious content or redirect users to scam pages. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample, limiting the analysis of specific malicious behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bringroverrightover.com/uploads/1/3/0/7/130739061/130739061.html#agresti+foundations+of+linear+and+generalized+linear+models
    • http://carsonbrace.com/uploads/1/3/0/4/130483811/4853688.pdf
    • http://thevitalogist.com/uploads/1/3/0/8/130873965/3590696.pdf
    • http://www.locoessentials.com/uploads/1/3/0/5/130588795/puvolenikubukit-nurazolaxikato-fobavi-fibegati.pdf
    • http://sticksandcones-outdoorfun.com/uploads/1/3/0/7/130776452/6322647.pdf
    • http://midwestairsoftgroup.net/uploads/1/3/0/6/130604542/f82754f2798.pdf
    • http://reachforthestars.info/uploads/1/3/0/2/130289304/dixarogoraniw-ximuj.pdf
    • http://phenomchild.com/uploads/1/3/0/6/130639030/xufowuwik.pdf
    • http://sexeparadisco.com/uploads/1/3/0/6/130604358/0b80bd0.pdf
    • http://happynursedani.com/uploads/1/3/0/2/130272241/kijonoxufipitad.pdf
    • http://wupbl.com/uploads/1/3/0/5/130539756/f577f.pdf
    • http://dustydiamondscleaningservice.com/uploads/1/3/0/5/130551526/busokigimurisi-nadipop-moxenawika-xepepama.pdf
    • http://diraacademy.com/uploads/1/3/0/7/130776177/garamebur-tejorobuk.pdf
    • http://southcoastgourmetgifts.com/uploads/1/3/0/5/130588222/pikepuwijavupixepe.pdf
    • http://sevenchurcheshoney.com/uploads/1/3/0/5/130588336/c96d27beb6725.pdf
    • http://74-123-78-154.mgwnet.com/uploads/1/3/0/8/130813917/ecf38bd6591a228.pdf
    • http://emeraldzen.com/uploads/1/3/0/8/130813497/669ba.pdf
    • http://053748270.com/uploads/1/3/1/4/131406248/sikebizirepe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cb6d.bin
58a370b20133377c4609dd152e5ca5a4a47e5e03c9538b8bc61ca2f8e2e3f161
pdf-font-stream PDF embedded font (sfnt) at offset 0xCB6D 8304 bytes