Malicious PDF — malware analysis report

Static analysis result for SHA-256 46435bc291442e27…

MALICIOUS

PDF

60.7 KB Created: 2020-03-12 03:55:22 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d2ccdc5b15d8cc1db63981f2daf2ec08 SHA-1: 64fff1b2427b59e1c5d957c848ab87ea4d2f933f SHA-256: 46435bc291442e278b4ef115076050f085adf27652ba164f7338b0d135c8edcb
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains numerous embedded links to external websites, a common technique for SEO link farms used to distribute malicious content. The document body, though heavily obfuscated, contains URLs that appear to be part of this link farm strategy. The ML classifier strongly indicates maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms the presence of a large number of external links, suggesting a distribution or redirection mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gz9c2.slpny.com/uploads/1/3/0/3/130313529/130313529.html#facebook+advertising+report+template
    • http://encyclobeerdia.com/uploads/1/3/0/4/130488165/fepagatap.pdf
    • http://smartkitchen.org.uk/uploads/1/3/0/3/130313252/1949559.pdf
    • http://medicalinsurance.co.uk/uploads/1/3/0/4/130483302/355199fd8c84d48.pdf
    • http://jusburritos.com/uploads/1/3/0/2/130270776/4670775.pdf
    • http://www.confederaterose.org/uploads/1/3/0/7/130738771/a2a08b.pdf
    • http://vancouvergaragerepair.com/uploads/1/3/0/5/130550951/09a8c8.pdf
    • http://bellasolcontrol.com/uploads/1/3/0/5/130551064/sunepatavusijukukeja.pdf
    • http://www.juliecorbeilrhn.com/uploads/1/3/0/7/130775756/0e19610cd970.pdf
    • http://sharpexteriors-ar.com/uploads/1/3/0/4/130435649/4064258.pdf
    • http://blueprintseo.com/uploads/1/3/0/7/130776331/lexagig-duxufibune.pdf
    • http://aharesidents.com/uploads/1/3/0/6/130604581/xutuporidonofeduj.pdf
    • http://goldendianara.com/uploads/1/3/0/8/130814237/f879bea66daf.pdf
    • http://ddcated-2-marketing-a.pleasingfood.com/uploads/1/3/0/6/130620501/2346058.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a0aa.bin
20d320369bff0554bcf61dc6fbf718ac87297bd93b858e7ec35f916e55c8af0e
pdf-font-stream PDF embedded font (sfnt) at offset 0xA0AA 10064 bytes
font_01_sfnt_off0000c500.bin
1b3f82cd74c5b6671cc0c0d4a6c7877b74bb57ca469b2a61ef541918e41af838
pdf-font-stream PDF embedded font (sfnt) at offset 0xC500 2652 bytes
font_02_sfnt_off0000ce68.bin
d0701945b924a16e8aa862fc080988071f6d43e3dc1b80d8bb841d10b86ee679
pdf-font-stream PDF embedded font (sfnt) at offset 0xCE68 16112 bytes