Malicious PDF — malware analysis report

Static analysis result for SHA-256 751b166a3db0068a…

MALICIOUS

PDF

61.2 KB Created: 2020-04-02 05:45:14 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: aac759c3d63509dfe532609d87b6ad51 SHA-1: 712b0eaff6c52a62803d5ff1e24c55cc2555bf65 SHA-256: 751b166a3db0068ad03f941ff4914fafefb582051551adbbe79f004cddd01403
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of embedded links, many of which point to other PDF files hosted on various domains. This behavior is indicative of a link farm or a mechanism to distribute further malicious content, likely intended to deceive users into downloading and opening additional malicious documents. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ecplusllc.com/uploads/1/3/1/4/131454051/131454051.html#atharva+veda+sanskrit+with+english+translation+pdf
    • http://torrintowindows.be/uploads/1/3/0/4/130489627/zabanovujasisasimuza.pdf
    • http://cdbtpsych.com/uploads/1/3/0/5/130588334/fakulepu.pdf
    • http://catherinejonespaediatricdietitian.com/uploads/1/3/0/9/130969874/5745012.pdf
    • http://lovefalkirk.com/uploads/1/3/0/5/130590724/a88e95bb3.pdf
    • http://wonderproduct.jp/uploads/1/3/0/3/130379352/5019610.pdf
    • http://neilswriting.com/uploads/1/3/0/6/130605212/wuxixagivep_nifatal.pdf
    • http://bucketsofbrassandcopper.com/uploads/1/3/0/5/130550768/mitojijovo.pdf
    • http://the7thwindowstore.com/uploads/1/3/0/2/130273733/7797248ba421622.pdf
    • http://njbrickwork.com/uploads/1/3/0/6/130605143/zukufevawiboja-wawagidawunon-sutujap.pdf
    • http://theinterdependentorganization.com/uploads/1/3/0/3/130379213/1140953.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008b06.bin
0045aa7f72ef36e05f35b8969652bc9579c1604066ed9e5d639d42d308227623
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B06 7948 bytes
font_01_sfnt_off0000a9f3.bin
1e40e98b03ddbccc880877284e0fa26e3d6152a239967a2ea6f35cc1f6244ff9
pdf-font-stream PDF embedded font (sfnt) at offset 0xA9F3 2604 bytes
font_02_sfnt_off0000b2ee.bin
0f656d154c5d73af7433414f04fc54e5b39641d30ad529dde5ca8229ae456640
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2EE 17280 bytes