Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c6dc06f598a560d…

MALICIOUS

PDF

42.3 KB Created: 2020-03-30 13:38:00 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: c573fedd7644a42d73a234fa0484eb39 SHA-1: eeb1c0cc0cf17c1fbc425f07992300e9df4f5777 SHA-256: 7c6dc06f598a560dffe548af0109d6eac0072973a562c34f1c2c122a176ef426
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO manipulation tactic. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the sheer volume of outbound links suggests an attempt to redirect users to potentially malicious content or to manipulate search engine rankings.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lists.accordionapocalypse.com/uploads/1/3/1/3/131379405/131379405.html#before+anna+todd+book+quotes
    • http://tjchildcare.com/uploads/1/3/0/7/130776003/9180861.pdf
    • http://teaismedicine.org/uploads/1/3/0/7/130739651/vijadukexeb.pdf
    • http://premoilcorp.com/uploads/1/3/0/2/130291707/pepisowosidi_wabomipomizizof_jifix.pdf
    • http://pattenacademy.net/uploads/1/3/0/7/130775557/wopexoju-lorodavon-mudupoj.pdf
    • http://lucindalyonsfineart.com/uploads/1/3/0/3/130379625/lujadage_fudibumuzodufox.pdf
    • http://storikusteven.eu/uploads/1/3/0/8/130874429/b6c6f3f.pdf
    • http://sanctuarymassage.info/uploads/1/3/0/4/130436492/8260014.pdf
    • http://seniorknows.com/uploads/1/3/0/4/130488812/63b0002d.pdf
    • http://virtuousink.net/uploads/1/3/0/3/130379431/c6da8df93d1970.pdf
    • http://freiyajoaillerie.com/uploads/1/3/1/1/131163851/a3048d80.pdf
    • http://cuppaconnection.com/uploads/1/3/0/4/130476348/f4fd3a36eda04ca.pdf
    • http://cynthiasuedeihl-butterworth.com/uploads/1/3/0/5/130539492/lavodemirolas.pdf
    • http://devinhyltonphotography.com/uploads/1/3/0/5/130543545/mixajinizotiw-sufala-ribokufikibosax-kazixotitivezi.pdf
    • http://khulaoncloud.com/uploads/1/3/0/7/130739816/zokogef_powijiralo.pdf
    • http://gallery-lesmemoiresdejacqmotte.com/uploads/1/3/0/7/130739618/6727926.pdf
    • http://larissamae.com/uploads/1/3/0/8/130814715/xipexoru.pdf
    • http://dqwoiq.com/uploads/1/3/0/4/130436242/3141415.pdf
    • http://javiermunhosandrealarrude.com/uploads/1/3/0/6/130622033/maziwutoz.pdf
    • http://rentthreads.com/uploads/1/3/0/5/130540401/e30181a2.pdf
    • http://gloriamata.com/uploads/1/3/0/5/130588936/kabelakapoteb_duforudurixon.pdf
    • http://imbeautifultoo.shop/uploads/1/3/0/7/130739614/rexujoxudevuse-botuvit.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000741d.bin
66fc14dc54a8e3d80d0ebb8b0456504471d43eaec2abc1d03bea73495dc02400
pdf-font-stream PDF embedded font (sfnt) at offset 0x741D 7308 bytes
font_01_sfnt_off000090a2.bin
87fd6b1a35a64f5c2d30902eea89631a9c05d6b36ef70c6d0cee4d2ad867525e
pdf-font-stream PDF embedded font (sfnt) at offset 0x90A2 2596 bytes