Malicious PDF — malware analysis report

Static analysis result for SHA-256 50d0f9b3be48177b…

MALICIOUS

PDF

32.4 KB Created: 2020-06-15 07:25:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f8b327fea96c83b785fb01e4ec5aeb8a SHA-1: 5fbdd13fe4803d3539098bf19edcd507e4e387bf SHA-256: 50d0f9b3be48177be8f1e88f3a14da1b7df633fe6330d30bd3911d20a951a5df
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. These links point to various PDF files hosted on different domains, suggesting a tactic to manipulate search engine results or distribute malicious content. The document body, though partially corrupted, contains references to 'Blackberry curve 8130 manual' and the authoring application 'wkhtmltopdf', which may be part of a lure to entice users to click on the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://avretoday.com/uploads/1/3/0/9/130969959/130969959.html#blackberry+curve+8130+manual
    • http://74-123-75-237.mgwnet.com/uploads/1/3/0/5/130551046/fusareva.pdf
    • http://worldrugbyjournal.com/uploads/1/3/1/4/131407704/gumitotafelutit-xugemar.pdf
    • http://blog.nextevent.live/uploads/1/3/0/5/130539260/rufulefamevawoxuza.pdf
    • http://successorsolution.com/uploads/1/3/0/2/130287988/9531907.pdf
    • http://holisticfreedom.shop/uploads/1/3/0/4/130483900/jejetokavazadeze.pdf
    • http://bluerosehealingcenter.com/uploads/1/3/0/4/130493714/setij.pdf
    • http://cuttingedgelawncare.org/uploads/1/3/0/6/130605237/xufijoso.pdf
    • http://peireptileexpo.ca/uploads/1/3/0/5/130590375/7c9f0ad.pdf
    • http://staging2.memassweets.com/uploads/1/3/1/4/131453028/pugaxipopojebujogove.pdf
    • https://majemim.files.wordpress.com/2020/06/39948631744.pdf
    • https://vazomirawan.files.wordpress.com/2020/06/16296272844.pdf
    • https://wididoripelo.files.wordpress.com/2020/06/vewubivezemoxinib.pdf
    • https://lezuvovefoga.files.wordpress.com/2020/06/nigalarosejenizo.pdf
    • https://fiwukezebara.files.wordpress.com/2020/06/20583696390.pdf
    • https://pevuwuke.files.wordpress.com/2020/06/42768799431.pdf
    • https://nemalakobi.files.wordpress.com/2020/06/zoribunexovibufa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053de.bin
d11361eb615edf1fc282fc3d25bda38254f12ce53625b291177186c831069482
pdf-font-stream PDF embedded font (sfnt) at offset 0x53DE 10084 bytes