Malicious PDF — malware analysis report

Static analysis result for SHA-256 6613f2752a8b5bbe…

MALICIOUS

PDF

54.3 KB Created: 2020-03-22 12:22:11 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d1869692e90797f2b605a83825fc29dc SHA-1: 3884bd96b0ad0e57861efdcc84a570d08ba6f1ee SHA-256: 6613f2752a8b5bbe07ed2a9312bc3838d54a6bf3bb8b4a528a18218d728fa55b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF document contains a large number of external links to other PDF files hosted across numerous domains. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://assortedartistries.net/uploads/1/3/0/8/130874156/130874156.html#sistema+locomotor+humano+y+sus+partes
    • http://nvholidaybazaar.com/uploads/1/3/0/4/130483248/2899102.pdf
    • http://franchisepro.com.au/uploads/1/3/0/6/130621335/mupowi.pdf
    • http://247cardetailing.com/uploads/1/3/0/4/130483067/disiw.pdf
    • http://istaripictures.com/uploads/1/3/0/5/130589057/fedote.pdf
    • http://trisetfitness.com/uploads/1/3/0/4/130435873/d82d607df7f.pdf
    • http://campsierrastars.com/uploads/1/3/0/6/130620625/3865461.pdf
    • http://gadgets2go.org/uploads/1/3/0/8/130814402/kivaruliz_gidutopipi.pdf
    • http://amatowoodcrafts.com/uploads/1/3/0/3/130313117/7889115.pdf
    • http://tryshashby-rolls.com/uploads/1/3/0/7/130776692/gorukeve_kilutigupa.pdf
    • http://restaurantcat.com/uploads/1/3/0/7/130775432/mutijomoxefukole.pdf
    • http://aliahjan.co.nz/uploads/1/3/0/5/130550768/xupuzebuwoxu.pdf
    • http://billionaireamerican.com/uploads/1/3/0/7/130740164/501f86ac7afa291.pdf
    • http://www.dmfw223.com/uploads/1/3/0/5/130545895/9d0ba77d9.pdf
    • http://designedfx.com/uploads/1/3/0/5/130590436/94b81eee594.pdf
    • http://www.busybeesoapery.com/uploads/1/3/0/5/130590588/nabonetula.pdf
    • http://argylecultureeyewear.com/uploads/1/3/0/3/130313056/wijedobag.pdf
    • http://loninkprojects.nl/uploads/1/3/0/3/130323208/5283903.pdf
    • http://www.nana-ps-pearls.com/uploads/1/3/0/6/130621061/joxifor.pdf
    • http://melaniechartier.com/uploads/1/3/1/0/131069870/fupadiravosinuno.pdf
    • http://jonesii.xyz/uploads/1/3/0/2/130273987/wiwesexipul.pdf
    • http://financialaiduniversities.com/uploads/1/3/0/6/130639703/75dabdac47cf.pdf
    • http://paperbirchyoga.com/uploads/1/3/0/5/130590356/61d5dfcd93c6.pdf
    • http://www.gnosventure.com/uploads/1/3/0/6/130604295/zoterifomojuwupusiv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008b14.bin
4cb033503435d541439aa70c581f93dcd11d8680410e7145c052f5b006a14069
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B14 8820 bytes
font_01_sfnt_off0000aabc.bin
e91619dfd4c72a85464d95ef1ba4e67df13020651c42071bafbe521a61d9f7fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xAABC 2652 bytes
font_02_sfnt_off0000b423.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0xB423 16036 bytes