Malicious PDF — malware analysis report

Static analysis result for SHA-256 61f110315a3eeb67…

MALICIOUS

PDF

51.8 KB Created: 2020-05-20 02:02:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 864569b929ad6c01bd141f0834a15014 SHA-1: 26bf6a91ae3a229667a2ff4ca8942d6b802c6827 SHA-256: 61f110315a3eeb67fb1699ca05e057cec8dd15f9bc5c8eae142404ad4a6c2d57
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was identified as malicious by an ML classifier and contains a large number of external links, characteristic of a link farm. The primary purpose appears to be directing users to a collection of other PDF documents hosted across various domains, likely for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://silverhillconsulting.net/uploads/1/3/0/8/130874007/130874007.html#kokoro+ga+sakebitagatterunda+%25E0%25B8%258B%25E0%25B8%25B1%25E0%25B8%259A%25E0%25B9%2584%25E0%25B8%2597%25E0%25B8%25A2
    • http://lisadring.com/uploads/1/3/1/4/131483778/bfcddf3a1efb9d.pdf
    • http://impactforestry.net/uploads/1/3/0/7/130774969/2676012.pdf
    • http://desertjack.us/uploads/1/3/0/4/130436494/dilosipopegak.pdf
    • http://ilovethepain.com/uploads/1/3/0/9/130969407/240c6.pdf
    • http://somebernesemtdogs.com/uploads/1/3/0/2/130289638/disoturibaputi.pdf
    • http://greenleafchiropractic.com/uploads/1/3/1/4/131482992/suwazamodotej-lepavoxeveninu-sozan.pdf
    • http://fjbinc.com/uploads/1/3/1/3/131398156/8473939.pdf
    • http://lizzyandjane.com/uploads/1/3/1/4/131406440/dowipu.pdf
    • http://hydrologyskincare.net/uploads/1/3/0/5/130545827/376097.pdf
    • http://cleanpro888.com/uploads/1/3/1/3/131380582/badinuxemagagugid.pdf
    • http://gggoutdoorstv.com/uploads/1/3/0/5/130589146/8242706.pdf
    • http://mtview-ak.com/uploads/1/3/1/3/131383678/gozabudivuveb.pdf
    • http://palacearcade.online/uploads/1/3/1/6/131636629/dilowulu.pdf
    • http://ckeinsurance.net/uploads/1/3/0/9/130969441/zanujifatosibe.pdf
    • http://georgemeekdesigns.com/uploads/1/3/1/4/131406222/6706fff.pdf
    • http://yogawithkk.com/uploads/1/3/0/6/130621836/padarebisomaboz_gidisidu.pdf
    • http://lexaroma.com/uploads/1/3/1/4/131408248/38be618ab3.pdf
    • http://zerogravityuas.com/uploads/1/3/1/4/131406109/417a3.pdf
    • http://momentumbrands.org/uploads/1/3/0/5/130589186/vegabunep.pdf
    • http://evolutivesport.com/uploads/1/3/1/4/131453247/4001583.pdf
    • http://longbuilderscompany.com/uploads/1/3/0/3/130313366/11f1988e1a55.pdf
    • http://eltservicesllc.com/uploads/1/3/0/7/130776147/nugiligimaxudab.pdf
    • http://mawabuildingdreams.com/uploads/1/3/0/9/130969499/bamovela_mipevigita_pawuw_zipovir.pdf
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off0000759b.bin
02d5599408976e1895700d3f0b3efe2f62c8e34faae4deb8d64de74505b38838
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x759B 16672 bytes
font_01_sfnt_off0000a321.bin
f3da7bc9c9922f95b618d8c38ce411d758b0695fd295792bdf5e95beefd17769
pdf-font-stream PDF embedded font (sfnt) at offset 0xA321 8628 bytes