Malicious PDF — malware analysis report

Static analysis result for SHA-256 546a8ec909dd2c63…

MALICIOUS

PDF

51.0 KB Created: 2020-03-23 10:57:41 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 38a7394af7a61d9759c41599fd60c782 SHA-1: 439e91ea5fb577cd35cac6eb2581996099623587 SHA-256: 546a8ec909dd2c63f5c3054a7f5d620642e616aeb318a81123324ee73260b025
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, contains text related to 'Wings of Fire books' and wkhtmltopdf, suggesting a lure to a seemingly innocuous topic. The primary function appears to be directing users to a vast network of URLs, likely for SEO spam or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://reedalec.com/uploads/1/3/0/3/130323764/130323764.html#wings+of+fire+books+in+order+1-13
    • http://www.laihlasmum.com/uploads/1/3/0/5/130590140/tefotezir.pdf
    • http://www.myaishaalzaabi.com/uploads/1/3/0/6/130639924/fexuziwanef.pdf
    • http://enchantingtherapies.com/uploads/1/3/0/2/130287289/6682406.pdf
    • http://damiautopflege.ch/uploads/1/3/0/8/130873876/vipul.pdf
    • http://impeccablyhandmade.com/uploads/1/3/0/7/130739146/xutuvorop_wavidiba.pdf
    • http://ready2mediate.com/uploads/1/3/0/7/130739103/2747660.pdf
    • http://myessentialguide.com/uploads/1/3/0/7/130739811/9587559.pdf
    • http://bostonerrandservices.com/uploads/1/3/0/3/130313363/pakowufu_giwimozuweju.pdf
    • http://qianyiyulechengdailizhuce.f18.ebkf.org/uploads/1/3/0/8/130814219/7136928.pdf
    • http://simplytc4me.com/uploads/1/3/0/7/130776719/7710432.pdf
    • http://childrensxmasparty.fun/uploads/1/3/0/7/130739718/4744331.pdf
    • http://newframeofmind.com/uploads/1/3/0/2/130287835/1a6b3.pdf
    • http://romanticcaliforniacoast.com/uploads/1/3/0/7/130776811/5e5010f497772d.pdf
    • http://watar-ksa.com/uploads/1/3/0/6/130604949/7d4026cad0c3d.pdf
    • http://www.suttonsclassiccars.com/uploads/1/3/0/5/130551564/5320544.pdf
    • http://www.healthymomninjawarrior.com/uploads/1/3/0/7/130739211/jitot_sukudapawix.pdf
    • http://haddiepiephotography.com/uploads/1/3/0/4/130435842/8e8f489d5971dc4.pdf
    • http://www.qixingtanglang.com/uploads/1/3/0/4/130489052/2031816.pdf
    • http://cforcinema.org/uploads/1/3/0/6/130621298/sanuli.pdf
    • http://statewidefacilitiesservices.com/uploads/1/3/0/6/130605041/tufejuwepanok-musugabinapux-xokurozixajibuf-wemilejenuso.pdf
    • http://allstarroad.com/uploads/1/3/0/5/130589122/wirixogalowowivib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000084af.bin
67ff3c86f5814021eb9c14065b0597611ba6ba6ca8558bed803f49d5093b52de
pdf-font-stream PDF embedded font (sfnt) at offset 0x84AF 9352 bytes
font_01_sfnt_off0000a75c.bin
b70ed2bc54d0771f5ebdc02779674387161dbf9fa33dcd8e164b3b38dfc2a238
pdf-font-stream PDF embedded font (sfnt) at offset 0xA75C 16508 bytes