Malicious PDF — malware analysis report

Static analysis result for SHA-256 46b56ed37ae0f1a0…

MALICIOUS

PDF

51.3 KB Created: 2020-04-16 20:25:56 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 08436a85dbbb2ec436017d4f3eab3ab2 SHA-1: 4b8ef6b6919f70fe92e3a00ed595cc77eefee772 SHA-256: 46b56ed37ae0f1a0b94e88c35cd3a007d251f70d081b5ae084893a54ba537887
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The ML classifier also strongly indicated maliciousness. The document body contains text related to 'Android api level usage statistics' and 'wkhtmltopdf', which appears to be a lure to disguise the true malicious intent of hosting a link farm. The primary goal seems to be directing users to a large number of external URLs, likely for SEO manipulation or to host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jenroncorp.com/uploads/1/3/0/7/130775261/130775261.html#android+api+level+usage+statistics
    • http://atchhc.org/uploads/1/3/1/4/131407357/bimaxu.pdf
    • http://cactusroseranchwear.com/uploads/1/3/0/6/130640116/a1008e92af.pdf
    • http://antelope3.com/uploads/1/3/1/4/131452922/630254.pdf
    • http://bidbradley.com/uploads/1/3/0/5/130539846/vitojogop_kevuwifatib_wakos_bareperab.pdf
    • http://bigbobbeers.com/uploads/1/3/0/2/130271229/2467475.pdf
    • http://tacsatsupport.com/uploads/1/3/1/6/131637074/nurijoniminixoduvodu.pdf
    • http://delgadillonews.com/uploads/1/3/1/1/131164324/jopag.pdf
    • http://iatw.net/uploads/1/3/0/7/130775475/6388238.pdf
    • http://mercadohuanacaxtle.com/uploads/1/3/0/4/130436094/fovegan.pdf
    • http://fracturedoptics.com/uploads/1/3/0/5/130550928/687556.pdf
    • http://hakeemfowler.com/uploads/1/3/1/4/131407247/3305608.pdf
    • http://asmallundertaking.com/uploads/1/3/0/2/130272352/b475a658d3.pdf
    • http://bidbradley.com/uploads/1/3/0
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008991.bin
61048839b42870026ca06032979666a1198b8f2692918e504e9a2968208862b3
pdf-font-stream PDF embedded font (sfnt) at offset 0x8991 8424 bytes
font_01_sfnt_off0000a9d2.bin
a9a0cbdd47af2ea2cff5a4bf325ba0f4e4018825c54b81399ff3f9505b21a896
pdf-font-stream PDF embedded font (sfnt) at offset 0xA9D2 16088 bytes