Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d23f0aef3eab750…

MALICIOUS

PDF

41.0 KB Created: 2020-03-11 08:49:06 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: e4f302b15161bb36b3aca5cb2614334b SHA-1: 45c8a0068947cdf1c347ea9c15a7b489389df120 SHA-256: 5d23f0aef3eab7507b9346605605730f92372cddeb6a086c5d2571d4f13dc827
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, many of which point to external PDF files hosted on various domains. The document body, though heavily obfuscated, contains text related to 'Airtel digital tv channel selection' and includes a QR code lure, suggesting a phishing or redirection attempt. The ML classifier strongly flagged this PDF as malicious, and the sheer volume of external links indicates a link farm or redirection strategy.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://74-123-79-170.mgwnet.com/uploads/1/3/0/7/130739664/130739664.html#airtel+digital+tv+channel+selection
    • http://dansconcept.com/uploads/1/3/0/8/130813524/rixibexokebizifi.pdf
    • http://freharrodcorporation.com/uploads/1/3/0/2/130288383/lunimum_gesemiko.pdf
    • http://www.hg-virtual.com/uploads/1/3/0/7/130776055/5371279.pdf
    • http://nlwatercolor.net/uploads/1/3/0/7/130740462/pebuwofagumew_xadabe_sarofekunu_sabevese.pdf
    • http://ericberis.com/uploads/1/3/0/5/130547078/5013614.pdf
    • http://www.guerillaconsultantgroup.com/uploads/1/3/0/7/130775672/331097.pdf
    • http://sunsteellogistics.com/uploads/1/3/0/5/130550980/3749678.pdf
    • http://theluckyfewbooksandfundraising.com/uploads/1/3/0/4/130476332/4967532.pdf
    • http://phillycredithelp.com/uploads/1/3/0/7/130776126/datopulemowisex_tuvajada_nerenutagadoza_tubidubuwirefi.pdf
    • http://nextpathfinance.org/uploads/1/3/0/5/130539049/e9c7bc.pdf
    • http://z.ag/uploads/1/3/0/2/130270849/velipiwugugaku-fabuvilinifil-rumaxetu.pdf
    • http://hostmaster.slidemash.com/uploads/1/3/0/7/130774994/a46e24c0d570e8d.pdf
    • http://dragons-media.com/uploads/1/3/0/6/130639977/91fdd.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006bb1.bin
ffc3def5c3d0bda1dd600aa6633d80df551ba8093826dd1b47b6d76013865bca
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BB1 8288 bytes
font_01_sfnt_off00008bb4.bin
cbd0148da7bbbff23ec47194401c3f1c03d79ba7b8135dbef378e0828e3acd51
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BB4 1844 bytes