Malicious PDF — malware analysis report

Static analysis result for SHA-256 67216affd2dd4a42…

MALICIOUS

PDF

58.1 KB Created: 2020-04-16 21:09:12 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 986acbf4ad47aa46c9dd76d16ec98e27 SHA-1: 4cbaef3d3fc039624d182109418b8bc741862ffb SHA-256: 67216affd2dd4a425a1a85c2819e63dd5f403ee1caf925950839be21538918a7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for SEO poisoning or distributing malicious content. The ML classifier strongly indicated maliciousness, and the presence of multiple suspicious URLs suggests an attempt to redirect users to potentially harmful sites. No scripts were extracted, but the overall structure and URL distribution point towards a malicious document designed to lead users to external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9806

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nortthengirlinitiative.org/uploads/1/3/1/3/131383607/131383607.html#san+diego+citybeat+voter+guide+2018
    • http://survivalofthecutest.net/uploads/1/3/0/9/130968915/rozita.pdf
    • http://frankbardessono.com/uploads/1/3/0/6/130639949/a624561ae8c.pdf
    • http://simplyinspiredwords.com/uploads/1/3/1/0/131070051/nebaji.pdf
    • http://mikezamojski.com/uploads/1/3/0/6/130620601/pukabo-nazafitatiwo-kudizi-bofukovi.pdf
    • http://mariecurie.info/uploads/1/3/0/7/130739156/be9ec28cf9e8ef.pdf
    • http://susanacalachi.com/uploads/1/3/1/0/131071299/cdb41c0025c1e03.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bd01.bin
8700eb9f8397e326decf4a4ec0667c9fbc1ca1d0f420f82a9b3e088c8c89d2a2
pdf-font-stream PDF embedded font (sfnt) at offset 0xBD01 8300 bytes