Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c62484f981b0ff4…

MALICIOUS

PDF

44.8 KB Created: 2020-04-02 12:56:36 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 6ce993d57c1a888ec13bce98717114ff SHA-1: e8a230010a7ef7553f7e0896e79f9038df9826cc SHA-256: 6c62484f981b0ff4c83a34fd5c1e62e7b134e1271f9ce5d24a83946d6e0ff60d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO spamming operation. The ML classifier also strongly indicated maliciousness. While no scripts were explicitly extracted, the presence of numerous external URLs points towards a malicious intent to redirect the user to potentially harmful content or further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://riversidecountyhistory.org/uploads/1/3/0/5/130550995/130550995.html#3d+shapes+and+nets+test
    • http://elkaservice.net/uploads/1/3/0/5/130590461/082aab.pdf
    • http://highsupplycbd.com/uploads/1/3/0/6/130604693/ditixogub.pdf
    • http://gordongowlandjones.com/uploads/1/3/0/4/130488754/bewibefozodatuw-kopepinidikuz.pdf
    • http://brianandtodd.com/uploads/1/3/0/2/130272438/fosegifowilogizosu.pdf
    • http://educreditconsulting.com/uploads/1/3/1/4/131437143/5036266.pdf
    • http://ncmodern.com/uploads/1/3/0/5/130539742/kovodamujudul.pdf
    • http://www.timarupetresort.com/uploads/1/3/0/6/130603889/nedejen.pdf
    • http://fireflyinsuranceservices.com/uploads/1/3/1/0/131071047/6d5db.pdf
    • http://ashleydholley.com/uploads/1/3/0/5/130589328/3618641.pdf
    • http://artisticallysound.com/uploads/1/3/0/7/130776616/monawemiwitoj-likut-lavoxi-jiwagowuninuriv.pdf
    • http://adsl-63-204-18-60.benefitplans.org/uploads/1/3/0/7/130740258/1503426.pdf
    • http://pi4bi.com/uploads/1/3/0/9/130969438/tojefonesumodowekev.pdf
    • http://susan-ritz-art.com/uploads/1/3/1/3/131380205/wovevi-lelaza-bunazenub-tiwerit.pdf
    • http://host115.carmichaelnl.com/uploads/1/3/0/7/130775403/d297d84524d.pdf
    • http://narcanna.org/uploads/1/3/0/3/130313746/3276048.pdf
    • http://nurturetyme.org/uploads/1/3/0/2/130272281/nomava_dizalamefimazu_texuvinowaj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007869.bin
0196c85f43bd2ceae7fa865088688f636a17a039eab0127e61ba19ade85dbe53
pdf-font-stream PDF embedded font (sfnt) at offset 0x7869 8468 bytes
font_01_sfnt_off000098ef.bin
8380f0bdeb8964bf2467a56a0e6eeafa6deb1e629a7e09bf2a4d08f4046ea7c8
pdf-font-stream PDF embedded font (sfnt) at offset 0x98EF 3036 bytes