Malicious PDF — malware analysis report

Static analysis result for SHA-256 4230ec0b1a199efc…

MALICIOUS

PDF

48.6 KB Created: 2020-06-17 02:37:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f920037bfc4e9864cdcd755cf8c41b8a SHA-1: 8a558a46a39d42fc27402b02e6bb43cf6d8f4d44 SHA-256: 4230ec0b1a199efcbd7f0227e4d06ee85513c813765fde11db05b0b5c788efc6
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links, characteristic of a link farm designed to direct users to malicious websites. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains text related to 'Office access pdf' and references the wkhtmltopdf tool, suggesting a lure to trick users into visiting potentially harmful URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fssicgroup.com/uploads/1/3/0/7/130775134/130775134.html#office+access+pdf
    • http://el-equipo.com/uploads/1/3/0/6/130621196/werozisov_zijis_fonituteve_powufipos.pdf
    • http://yourscoliosis.com/uploads/1/3/1/4/131406049/7635537.pdf
    • http://ctlevent.com/uploads/1/3/0/3/130324440/zijoj_wenadewe_kipejisoju.pdf
    • http://wosenate.com/uploads/1/3/1/4/131453576/2924c56a15.pdf
    • http://pillargroundandtruthcogbf.org/uploads/1/3/1/4/131453853/xumevajubajadem_besebikofije.pdf
    • http://angelascupcakesandpupcakesinc.com/uploads/1/3/1/8/131871592/032601.pdf
    • http://living-twenty.com/uploads/1/3/0/3/130313319/4849509.pdf
    • http://kenna-kitchen.com/uploads/1/3/0/4/130483546/4cdfc9922b89.pdf
    • http://mail.teachenglishstepbystep.com/uploads/1/3/1/6/131637797/besizod.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007707.bin
756449f8066ebc3862ffd809d1031b6765b38bc40304c5613a4d3cb1fa4fc899
pdf-font-stream PDF embedded font (sfnt) at offset 0x7707 4540 bytes
font_01_sfnt_off0000867f.bin
0b7e7a79768373fb51c2863c4ebe01470f2069ce49771731fa83561d73e52133
pdf-font-stream PDF embedded font (sfnt) at offset 0x867F 22800 bytes