Malicious PDF — malware analysis report

Static analysis result for SHA-256 63b1d565f35cce69…

MALICIOUS

PDF

38.6 KB Created: 2020-03-26 02:23:14 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 533856aa25f85ac77e2b27dc0e698c90 SHA-1: d2da62a3b31b6829216498f803cd2fe460974303 SHA-256: 63b1d565f35cce69079f9a41cdebe5b32919b87ad70388074c2926f0ace32437
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, a technique often used for SEO spam or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness, and the presence of numerous embedded URLs supports this assessment. No scripts were extracted, but the link farm pattern suggests an attempt to drive traffic to potentially compromised or malicious web content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://diamonddogspetsitting.com/uploads/1/3/0/5/130590548/130590548.html#como+hacer+el+present+perfect
    • http://penelopehair.com/uploads/1/3/0/7/130774977/4912102.pdf
    • http://andreablackerby.com/uploads/1/3/1/3/131383373/gerakurobojigetut.pdf
    • http://officehelpsxoy.com/uploads/1/3/0/9/130969966/7792703.pdf
    • http://www.nwwriters.com/uploads/1/3/0/2/130272554/dbed9b7b2940af.pdf
    • http://cactusqueencrafting.com/uploads/1/3/0/8/130874615/1459134.pdf
    • http://matthew1924foundation.org/uploads/1/3/0/6/130604646/6af05b3.pdf
    • http://hostmaster.paullucaswriter.com/uploads/1/3/0/2/130288599/7136960.pdf
    • http://sobolagroup.com/uploads/1/3/0/6/130621472/9664331.pdf
    • http://affordablememories.org/uploads/1/3/0/4/130488476/7536ddc6540.pdf
    • http://medikka.com/uploads/1/3/0/7/130739056/benowulubuk.pdf
    • http://inspiredchic.net/uploads/1/3/0/7/130776646/4746605.pdf
    • http://explorebedale.com/uploads/1/3/0/3/130379287/tafiluporojufev-lewumapupe-timerilolinux.pdf
    • http://socialnetworkingdeveloper.com/uploads/1/3/0/7/130739678/fuxuxefugujif.pdf
    • http://texasfreedomcarriers.com/uploads/1/3/0/6/130620909/tifedamametef.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ce8.bin
166f1b03026c35edc1993096e64b8eb207f67e3000f4780a3472e58f9249d638
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CE8 8900 bytes