Malicious PDF — malware analysis report

Static analysis result for SHA-256 73103f6f90beaaae…

MALICIOUS

PDF

47.7 KB Created: 2020-03-29 09:52:24 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ba401edc0e39963a610ba4cd030053d9 SHA-1: fc8120bd14e7daea316059dd767ba82f2fe4abe4 SHA-256: 73103f6f90beaaae2d88234057d0bce8ca5634564f8e5640ad6550b0a965bae5
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document exhibits characteristics of a SEO link farm, generating numerous links to other PDF files hosted on various domains. The embedded URLs and the heuristic firings strongly suggest an attempt to manipulate search engine results and direct users to malicious content. The presence of a 'Password-protected archive handoff' heuristic indicates a common tactic to bypass security filters by encrypting the actual payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://adsl-63-204-18-21.benefitplans.org/uploads/1/3/0/4/130483520/130483520.html#ejemplo+de+planeaci%C3%B3n+de+una+secuencia+did%C3%A1ctica
    • http://gogetitconference.com/uploads/1/3/0/7/130776718/saxezulezuloba-tojozazuka.pdf
    • http://opencloud.us/uploads/1/3/0/7/130740378/ca356f27edbac8.pdf
    • http://burningfiddleproductions.org/uploads/1/3/0/5/130588506/900d0e6f96550.pdf
    • http://mta-sts.kyriegallery.com/uploads/1/3/0/2/130273845/josakelizotalox.pdf
    • http://inmanenergy.com/uploads/1/3/1/1/131164120/gomebutonemajerijudu.pdf
    • http://sendyouasong.com/uploads/1/3/0/6/130639853/nosebig-lunojinedenakas-zuraletunuvigu-juzaxilir.pdf
    • http://www.pattilooneypro.com/uploads/1/3/0/5/130539416/9587543.pdf
    • http://legacyfarmsllc.net/uploads/1/3/0/7/130739290/5f8c79044c6ad.pdf
    • http://optimalhospicefoundation.org/uploads/1/3/0/3/130323892/zalanu.pdf
    • http://brochuaccounting.com/uploads/1/3/0/3/130323817/9665903.pdf
    • http://toysdayout.com/uploads/1/3/0/4/130436242/3952212.pdf
    • http://www.aftris.com/uploads/1/3/0/5/130590435/fbc2494fc.pdf
    • http://suemoraes.com/uploads/1/3/0/6/130639400/muromaw_towesixid.pdf
    • http://bigislandxxx.com/uploads/1/3/0/2/130291373/xegatelum.pdf
    • http://faceiso.org/uploads/1/3/0/5/130551651/1774626.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007886.bin
ec986876e0d14dad3fbd5628073b03d2559a5fa1e5cb16b3074e39e20324f98f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7886 9376 bytes
font_01_sfnt_off000099fe.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x99FE 16036 bytes