Malicious PDF — malware analysis report

Static analysis result for SHA-256 71c4fac0a5e5ad56…

MALICIOUS

PDF

50.4 KB Created: 2020-03-31 04:10:43 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 94857a792e5dc1a9f1a115cbd4e5b7f5 SHA-1: 33bc3389f513f54baa754054c4f8090e7c508a3d SHA-256: 71c4fac0a5e5ad569f75668a9dce878f84fc05c15156412e446a2eb925889793
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing indicating a mass external PDF link farm, with numerous URLs pointing to various domains. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains URLs that are consistent with the link farm heuristic, suggesting the primary purpose is to redirect users to a large number of external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thehnossaproject.com/uploads/1/3/0/8/130814040/130814040.html#icd+10+code+for+ocular+myasthenia
    • http://kasvinkumppanit.fi/uploads/1/3/0/4/130476344/1658965.pdf
    • http://beadedandbodiedstore.com/uploads/1/3/1/1/131164555/xofazaforonuxe-bikezitufuruk-sakoresimotan-lepil.pdf
    • http://sunnyspotdoggrooming.com/uploads/1/3/0/5/130588230/7969303.pdf
    • http://imagery.solutions/uploads/1/3/0/7/130775742/wofugetuk-vatefopotavusid-musatodeluxija-pewinenepakuma.pdf
    • http://foothillhorseandpet.com/uploads/1/3/0/3/130379798/347ccecf20.pdf
    • http://lajollalouvre.com/uploads/1/3/0/7/130776861/xitovajibovumeziwux.pdf
    • http://my-sh-online.com/uploads/1/3/0/6/130603773/ribezopa.pdf
    • http://iffmerch.com/uploads/1/3/0/4/130476688/e31bc838.pdf
    • http://tlambandco.com/uploads/1/3/0/2/130270994/a4c83e.pdf
    • http://ammavegkitchen.com/uploads/1/3/0/3/130313610/zopatatux.pdf
    • http://neuvenicephoto.com/uploads/1/3/0/3/130379081/bevipawero_rekebuketixizi_pobuzemudijile.pdf
    • http://alexispercival.com/uploads/1/3/0/7/130739829/621a5.pdf
    • http://amyfazio4pa.com/uploads/1/3/0/9/130969260/moxopo.pdf
    • http://tutump.com/uploads/1/3/0/5/130551604/726fdfa94d80c9.pdf
    • http://gobeyondthepond.com/uploads/1/3/0/8/130873708/dubuxirezenikabug.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000793a.bin
746aae8e7cd57cb3ca880df353bcf39d9769713afdfd33068c0a9539c805b8e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x793A 7820 bytes
font_01_sfnt_off00009763.bin
3bc4186c134140c550a58bd49037b75bfbe8d656fd7a0ba0a83014c284a8a74e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9763 4512 bytes
font_02_sfnt_off0000a60a.bin
6db6d9634b9937aa3169e45592670fe9753bced9edc690faa32395a665744885
pdf-font-stream PDF embedded font (sfnt) at offset 0xA60A 16204 bytes