Malicious PDF — malware analysis report

Static analysis result for SHA-256 60e8ae102db4313c…

MALICIOUS

PDF

35.7 KB Created: 2020-03-08 09:55:20 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a5701842b91f2d365a5fdd962d1fc000 SHA-1: e6b018e63e5d5707b65aa3766a36f3ea2d28b9ac SHA-256: 60e8ae102db4313c37b3e4fe508ff8457cc1b739dde57b84b649e6cd6f7da368
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous embedded URLs pointing to external sites, a technique commonly used for SEO spam or phishing. The heuristic PDF_SEO_LINK_FARM specifically indicates a large number of external links within the document. The ML classifier also strongly flagged this PDF as malicious. While no scripts were directly extracted, the presence of embedded URLs suggests an attempt to redirect the user to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://74-123-72-57.mgwnet.com/uploads/1/3/0/4/130488759/130488759.html#ielts+general+reading+samples+2018
    • http://autodiscover.paulwruckconstructions.com/uploads/1/3/0/3/130323552/lejide_susujozofus_tepekunanamu_woruf.pdf
    • http://pulleyslearningacademyand.com/uploads/1/3/0/5/130588573/miziv-binasu-gowawixiwo-kivevubo.pdf
    • http://www.moorescience.org/uploads/1/3/0/3/130313191/furot_filili_parapedapezaful.pdf
    • http://geraldvirtbauer.org/uploads/1/3/0/4/130476691/3858413.pdf
    • http://www.ozcountry.net/uploads/1/3/0/8/130873860/5410762.pdf
    • http://stylogentlemensweekend.com/uploads/1/3/0/6/130639767/626361.pdf
    • http://reimaginedclassrooms.com/uploads/1/3/0/2/130291552/1230672.pdf
    • http://nadinesteklenski.com/uploads/1/3/0/7/130776032/77b28773d.pdf
    • http://www.moneyforpropertydamage.com/uploads/1/3/0/6/130604690/ee9c7720.pdf
    • http://eatforyears.com/uploads/1/3/0/4/130483748/050ede7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006346.bin
030c4e9b7438f06b0e114e303c5dca25d5aa41a7312601a9e280cc9eec9b6b3d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6346 7936 bytes