Malicious PDF — malware analysis report

Static analysis result for SHA-256 67dc7a95423d838f…

MALICIOUS

PDF

50.9 KB Created: 2020-04-09 09:42:31 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2020-09-24
MD5: d2d62747973f0c841caeb5cb00d0a8c9 SHA-1: 95df7de1b9c96ba9622a02b213670d4d866d0588 SHA-256: 67dc7a95423d838f8c4fddb6798b87ef6b41fdf94bf71873c6f7946fd7cefd4b
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, suggesting an attempt to manipulate search engine results or redirect users to potentially malicious content. The malformed stream length heuristic indicates potential exploit activity within the PDF structure. While no scripts were directly extracted, the presence of external links and the ML classifier's high confidence score point towards malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://exploreia.net/uploads/1/3/0/2/130289045/130289045.html#acordes+de+septima+para+piano PDF link annotation
    • http://circarenovationsny.com/uploads/1/3/0/6/130603865/8e21611c1090.pdfIn PDF document text
    • http://homefrontbuildershouston.com/uploads/1/3/0/6/130621893/8437aeacc8bc95.pdfIn PDF document text
    • http://magicalmomentsbymichael.com/uploads/1/3/0/4/130476320/toxelomudaz_mutisenovemo_ladexoz_rogijesem.pdfIn PDF document text
    • http://newyorktravelmedicine.com/uploads/1/3/0/6/130639126/4281706.pdfIn PDF document text
    • http://ryankingrealestate.com/uploads/1/3/0/5/130544387/womogotebelu.pdfIn PDF document text
    • http://classicfilmmachines.com/uploads/1/3/1/0/131070189/3802d3bc0ccc7.pdfIn PDF document text
    • http://marriageprom.com/uploads/1/3/0/4/130490056/laduza.pdfIn PDF document text
    • http://bnbmanager.ca/uploads/1/3/1/1/131164204/48c242169187.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007972.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7972 9820 bytes
SHA-256: fcc3ae6933f525a14150d82cfb5117a976354e06e09cca6df8cd18080703bb41
font_01_sfnt_off00009cf1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9CF1 2728 bytes
SHA-256: d06ebcbcdb4ed352c50cab8cb929577f65efcb11e61e3ca1a4110e031dd31aae
font_02_sfnt_off0000a6a9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA6A9 16280 bytes
SHA-256: 3341a5202a1663a321882bd7d191ef9e7c15e5cab9613238f556078b706efc7f