Malicious PDF — malware analysis report

Static analysis result for SHA-256 40c59e0f665803e7…

MALICIOUS

PDF

38.7 KB Created: 2020-03-24 03:58:37 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 2ae70e52456f522873cde7698225665c SHA-1: b743fca30f22b067b794be8630cae972611bc9c5 SHA-256: 40c59e0f665803e705197ee3c6097ac1c904caf6e0a2a08c8faa77307d70e4f5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or distribution network. The ML classifier also strongly indicated maliciousness. The primary attack pattern appears to be the distribution of content or further malicious payloads through this extensive link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://estudio-thuban.com/uploads/1/3/0/6/130604732/130604732.html#componentes+de+los+alimentos+constructores
    • http://cdhimpression.com/uploads/1/3/0/6/130639683/tevotepagozunir.pdf
    • http://www.andrewspink.org/uploads/1/3/0/5/130590367/85e4f7a7110.pdf
    • http://ileanfitness.com/uploads/1/3/0/6/130604233/zilovevibolip_fenago.pdf
    • http://hostmaster.dreamcatchersforgoldenwarriors.com/uploads/1/3/0/3/130323888/lopamegivegil_sosexiwevus_busoku.pdf
    • http://plantbasedpowercouple.com/uploads/1/3/0/2/130273978/megazadidukisas.pdf
    • http://nelancasterhub.org/uploads/1/3/0/7/130776399/tovurir.pdf
    • http://hostmaster.emcg.org.uk/uploads/1/3/0/3/130323445/xedevenoxitelo.pdf
    • http://theautismrowboat.com/uploads/1/3/0/4/130476736/linonabukemebidaris.pdf
    • http://mail.spokaneroofcleaningservices.com/uploads/1/3/0/6/130639867/foviliko.pdf
    • http://www.classicallyshort.com/uploads/1/3/0/3/130313741/d56c85288309a1.pdf
    • http://www.nidustheatrearts.co.uk/uploads/1/3/0/7/130776874/6aa20ee62e10a3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006585.bin
4b8fbe06d163ff77790f4d9e89921b2c46c875a1557c08a1b7f5ac12a511d07c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6585 7760 bytes
font_01_sfnt_off00008238.bin
e2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea
pdf-font-stream PDF embedded font (sfnt) at offset 0x8238 2652 bytes