Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d16de6845690413…

MALICIOUS

PDF

36.7 KB Created: 2020-03-28 12:18:04 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9768630aa0ce70e887265c44d3c6d961 SHA-1: 77bf8ac4d47ad758fbeae75eef6d3e55d572bf9c SHA-256: 5d16de6845690413085cc703c407e87235c100255d960ff6beaaaa9ec56d51f8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, many of which point to other PDF files with numeric slugs. This behavior is indicative of a link farm or SEO spam technique, likely intended to drive traffic to malicious or low-reputation sites. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://katanasushifh.com/uploads/1/3/0/4/130435548/130435548.html#que+es+ordenada+y+abscisa+al+origen
    • http://nuvisionabroad.com/uploads/1/3/0/2/130272428/vupidalobijo-dumidolesidir-modumeruv.pdf
    • http://cleancarbontechnologies.com/uploads/1/3/0/5/130588461/dosiwofifobexugu.pdf
    • http://jcjamison.net/uploads/1/3/0/5/130539105/pajujijopivovobu.pdf
    • http://vaylenclothing.store/uploads/1/3/0/2/130289540/galobu.pdf
    • http://eastlouisville.preview.pethealthnetworkpro.com/uploads/1/3/0/5/130551239/vunokivi_wojuxixagug.pdf
    • http://vevey-reveillon.ch/uploads/1/3/0/2/130272856/9f53f2c.pdf
    • http://lewistermitecontrol.com/uploads/1/3/0/7/130738786/964118d761cf.pdf
    • http://azfrightpass.com/uploads/1/3/0/6/130604984/8039883.pdf
    • http://gmbverifier.com/uploads/1/3/0/8/130813787/d909061f81d1f.pdf
    • http://kartasongs.com/uploads/1/3/0/4/130477110/xojojozibom-diwakomisizapaw.pdf
    • http://donoprealty.com/uploads/1/3/0/9/130969316/pitenivebojoparu.pdf
    • http://comicstripbuilder.com/uploads/1/3/0/7/130738885/6675575.pdf
    • http://remaxsellshomes.com/uploads/1/3/0/8/130814992/776086.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066cb.bin
c6b220eecebc4467e5c6e7625bec228a2186baccd3d037d1e8bbe0f6c83b9fb7
pdf-font-stream PDF embedded font (sfnt) at offset 0x66CB 8512 bytes