Malicious PDF — malware analysis report

Static analysis result for SHA-256 7910ecbf9f33c135…

MALICIOUS

PDF

48.7 KB Created: 2020-04-01 20:11:07 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a59a82b1611cd2acc499b8194ea538d0 SHA-1: fe14b2f61efa775e67c8f42a56335c414d8bc27a SHA-256: 7910ecbf9f33c135b60fdfeb01a02eebc055094cbac48e67278232ed90f9df8d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to manipulate search engine results or redirect users to malicious content. The ML classifier also strongly indicated maliciousness. The embedded URLs are likely used to host further stages of the attack or to distribute malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sergent-major-bonn.de/uploads/1/3/0/9/130968931/130968931.html#el+sistema+educativo+nacional+fernando+martinez+paz+pdf
    • http://thelivechatcafe.com/uploads/1/3/0/2/130288602/pegox.pdf
    • http://plegendbeats.com/uploads/1/3/0/5/130551366/xozapexapemidefokibi.pdf
    • http://greenaccountingservices.us/uploads/1/3/0/7/130739343/roweb.pdf
    • http://lenacpn2save.com/uploads/1/3/0/7/130776755/4796870.pdf
    • http://internationalfilmbroker.com/uploads/1/3/0/3/130379757/sojilutelufanibepa.pdf
    • http://instantpsychologytools.com/uploads/1/3/0/7/130738758/2643022.pdf
    • http://mrsmediation.com/uploads/1/3/0/6/130639552/580991.pdf
    • http://hamiltoncitymobilehomepark.com/uploads/1/3/0/5/130542729/c14c6220.pdf
    • http://jojogadgetgirl.com/uploads/1/3/0/8/130813876/8075342.pdf
    • http://thomasnazario.com/uploads/1/3/0/8/130813458/15285fb4cbff.pdf
    • http://villa-nostalgi.no/uploads/1/3/0/6/130640181/7d39483be458c.pdf
    • http://normansigns.com/uploads/1/3/1/3/131381614/kirorogolezuragolag.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f85.bin
137c9626cf495ff228cd284ae4ebf3ae9cf4a76505cd75a3a5bb2e62261a0cf3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F85 10556 bytes
font_01_sfnt_off000094c1.bin
e91619dfd4c72a85464d95ef1ba4e67df13020651c42071bafbe521a61d9f7fc
pdf-font-stream PDF embedded font (sfnt) at offset 0x94C1 2652 bytes
font_02_sfnt_off00009e28.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x9E28 16036 bytes