Malicious PDF — malware analysis report

Static analysis result for SHA-256 76bd7f8d84ec19c4…

MALICIOUS

PDF

46.9 KB Created: 2020-06-22 03:50:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bbd4011f02d0d127fc53aac500b0b86e SHA-1: 6d75717c33e87f0a8d55bef634d96f7c5c10023f SHA-256: 76bd7f8d84ec19c42cf4311eda91fab463c001a42e41798aad80c42891a9b182
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document is classified as malicious by an ML model and contains a large number of external links, indicative of a link farm or SEO poisoning tactic. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to potentially harmful content hosted on numerous domains. The primary intent appears to be traffic generation or hosting malicious payloads via these external links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://warsoftherosesfederation.co.uk/uploads/1/3/0/7/130775537/130775537.html#south+of+france+travel+guide
    • http://perlustrate.org/uploads/1/3/0/6/130621045/5740557.pdf
    • http://autodiscover.turningpointbaptistchurch.org/uploads/1/3/1/4/131412290/4949889.pdf
    • http://invado830.com/uploads/1/3/0/8/130814219/jodofa.pdf
    • http://house-2homeinspections.com/uploads/1/3/0/2/130291475/zanimevekap-dimubu-wezusagipu-xubes.pdf
    • http://journeyspromise.com/uploads/1/3/0/8/130874634/1f21c.pdf
    • http://mail.fatherjim.com/uploads/1/3/0/8/130874629/50f821448a331c.pdf
    • http://upwardtrends.net/uploads/1/3/1/8/131856409/fojaxojefufewo_mones_lofaxanemitat.pdf
    • http://cwbcellijay.org/uploads/1/3/1/6/131606289/sazadudam-bopuwudilufe.pdf
    • http://warren.fyi/uploads/1/3/1/4/131454521/2551992.pdf
    • http://tommylinkskonsult.com/uploads/1/3/0/3/130323743/jufebazev.pdf
    • http://lra.org/uploads/1/2/9/4/129455080/129455080.html?vintage
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000078d7.bin
751f177150d56853c9d2f127b81f19d9e05aa45a28cb0e7ed4433bed62597971
pdf-font-stream PDF embedded font (sfnt) at offset 0x78D7 5152 bytes
font_01_sfnt_off00008a4e.bin
844f162154a203506db6dab133af8d188dfe21b0aff1e36b38a5f8165575dc99
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A4E 11100 bytes