Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d7f232a8fe96fc7…

MALICIOUS

PDF

81.5 KB Created: 2021-03-30 09:58:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8b9c1af1d453f967396bbcd447588f93 SHA-1: 3bcacd18832574faeb44ca981eeebb15fa0e68f7 SHA-256: 6d7f232a8fe96fc7760304a736e986d6dd26936d12cbd0a7f7c31922c63aa6c1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous external links, a technique often used for SEO manipulation and to direct users to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' specifically indicates a mass external PDF link farm, suggesting an attempt to artificially boost search engine rankings or distribute malware. The presence of embedded URLs further supports the malicious intent of directing users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9954

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/wix?keyword=tbc+fishing+guide
    • http://guitar.su/twilight_breaking_dawn_story_summaryvepzf.pdf
    • https://cdn.sqhk.co/mipekakiri/khhajb4/77301802005.pdf
    • http://chisto-chisto52.ru/dyson_dc25_vacuum_cleaner_user_manualw4bct.pdf
    • http://donbetosstreettacos.com/load_data_analysis_toolpak_excel_20161nxgv.pdf
    • https://cdn.sqhk.co/nekuripafi/egiGhjA/xamexuwazeporixapuniwujik.pdf
    • https://cdn.sqhk.co/rotexopapi/bNKja29/police_car_coloring_book.pdf
    • https://cdn.sqhk.co/pixafosabow/gmBkiaP/japan_taxi_coupon_code_foreigner.pdf
    • https://cdn.sqhk.co/nepofigiper/IWMjihb/macao_casino_fish_slots_on_facebook.pdf
    • https://cdn.sqhk.co/tudifemumopi/giekiff/57662470268.pdf
    • https://cdn.sqhk.co/baxoladipezu/MjhWidJ/79421981274.pdf
    • https://cdn.sqhk.co/puroneruk/jfqjihq/44542919964.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/fedojigudaj/bosch_washing_machine_service_near_me.pdf
    • https://s3.amazonaws.com/jiwisigetizoxif/biology_book_class_12_cbse.pdf
    • https://c140f178-ee45-427e-91fe-a3c5f821f67e.filesusr.com/ugd/ebc5f9_de4f1fc9b9544ddd85194ff369ad1576.pdf?index=true
    • https://s3.amazonaws.com/rodiligarexo/45263705742.pdf
    • https://7be326e9-a1fd-4761-a84c-83c904220737.filesusr.com/ugd/37e945_70595b9c58e0445b8b21175860c7b29d.pdf?index=true
    • https://dd7ee03d-3646-4e01-a1e1-4c0a7e2c9e57.filesusr.com/ugd/d7ba0f_5ec813a9d5ba4fce98564c6289a1e520.pdf?index=true
    • https://486bfeb6-87d8-40a3-812f-3449909c9139.filesusr.com/ugd/81b904_e7334335fec54a7aaf20ddd13a3b5f89.pdf?index=true
    • https://s3.amazonaws.com/ravuxudibure/office_365_quarantine_report_settings.pdf
    • https://217ba8a6-026c-4a9e-b1ce-2eadff0a4a08.filesusr.com/ugd/3d7af5_0627ca4216354214ae661a1e488187ee.pdf?index=true
    • https://s3.amazonaws.com/dalava/pigimox.pdf
    • https://s3.amazonaws.com/sepawi/33361890547.pdf
    • https://s3.amazonaws.com/pululusodogi/voxujatotatole.pdf
    • https://s3.amazonaws.com/zumezeviwakiz/kuzaziluvexawisiwawij.pdf
    • https://s3.amazonaws.com/bubeto/34314653356.pdf
    • https://s3.amazonaws.com/zarelusipofox/74245497621.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f56b.bin
ec5812fedec0d3e6c1a5ff97afb981b55bc41b140dabde6b4dc00a4f2a9f282e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF56B 4728 bytes
font_01_sfnt_off00010569.bin
58e030e7b949cc56eea31a4e7ff6a18fbeeb86cf1a174736ea8839002990ff88
pdf-font-stream PDF embedded font (sfnt) at offset 0x10569 10816 bytes
font_02_sfnt_off00012a56.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A56 4324 bytes