Malicious PDF — malware analysis report

Static analysis result for SHA-256 8441ebdf5294a474…

MALICIOUS

PDF

53.3 KB Created: 2020-03-26 12:59:05 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2020-09-07
MD5: e92d635b54c321b0f42ece313d39883a SHA-1: a0a426e5928e063592c25bcfd6d05f0d64a06f10 SHA-256: 8441ebdf5294a474a84cb78b27b9d0f2bf5994d23f6a7c954058b050fb48b324
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a large number of external links, many of which point to other PDF files hosted on various domains. This suggests a link farm or SEO manipulation tactic. The primary URL, http://absystemsllcscam.com/, is likely intended to host malicious content or redirect the user to a phishing page. No scripts were extracted, but the ML classifier strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://absystemsllcscam.com/uploads/1/3/0/7/130775828/130775828.html#cuales+son+los+elementos+de+una+ficha+de+resumen PDF link annotation
    • http://ebindependent.com/uploads/1/3/0/2/130271259/091fc3.pdfIn PDF document text
    • http://tijdvoormassage.nl/uploads/1/3/0/7/130740371/bogalosude.pdfIn PDF document text
    • http://www.exdiscount.com/uploads/1/3/0/6/130620549/f7cc9367d4afd.pdfIn PDF document text
    • http://brandimcmillan.com/uploads/1/3/0/3/130313169/6247500.pdfIn PDF document text
    • http://lovejoybreathwork.com/uploads/1/3/0/5/130541744/a8c01d4eff96962.pdfIn PDF document text
    • http://merz-verlag-en.com/uploads/1/3/0/2/130289262/ddb0939f4a4.pdfIn PDF document text
    • http://mychemicalguys.com/uploads/1/3/0/6/130603815/6b15c5.pdfIn PDF document text
    • http://hippieretreat.org/uploads/1/3/0/6/130639055/9741955.pdfIn PDF document text
    • http://lv01.hendersonchamber.com/uploads/1/3/0/3/130313531/9394683.pdfIn PDF document text
    • http://grassrootsdocu.com/uploads/1/3/0/4/130483810/759421.pdfIn PDF document text
    • http://amazingcloaker.com/uploads/1/3/0/2/130271002/somamakir_tinajakitaseni_limari.pdfIn PDF document text
    • http://cpanel.coffeeloud.com/uploads/1/3/0/9/130969604/burebaladene.pdfIn PDF document text
    • http://grafixcity.com/uploads/1/3/0/6/130604580/noxufasakosokodimog.pdfIn PDF document text
    • http://makingkidsmatterllc.com/uploads/1/3/0/6/130622007/tixibamemibelofekoka.pdfIn PDF document text
    • http://lemurjewels.net/uploads/1/3/0/8/130814851/9673325.pdfIn PDF document text
    • http://best-office-bueroservice.de/uploads/1/3/0/5/130545882/7b01554889a.pdfIn PDF document text
    • http://www.clayandgrover.com/uploads/1/3/0/6/130604820/pibusokutaguj-lisuzu.pdfIn PDF document text
    • http://shicachic.com/uploads/1/3/0/5/130590162/c6ef31ecdd0b82f.pdfIn PDF document text
    • http://ladieseducationservices.com/uploads/1/3/0/7/130738841/b9ce6ffaf9c968a.pdfIn PDF document text
    • http://eaglesnesthomeinspectionsllc.com/uploads/1/3/0/5/130539393/retuga_davuvitod_zoleterekizivo.pdfIn PDF document text
    • http://www.wildteraniafarm.com/uploads/1/3/0/5/130540397/4368095.pdfIn PDF document text
    • http://plusconstruction.org/uploads/1/3/0/4/130476013/9afc4586.pdfIn PDF document text
    • http://jessemarks.nl/uploads/1/3/0/7/130740086/f71ee.pdfIn PDF document text
    • http://www.eipef.eu/uploads/1/3/0/3/130312919/vamumipiz_kowilamisavomag_pezupav_tuvawasujen.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008d17.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8D17 9692 bytes
SHA-256: 640b65c065dd1cc6f02f47e0a9cbe2d85373ca6461e5086b2cf51b352d424140
font_01_sfnt_off0000af98.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAF98 16168 bytes
SHA-256: 0437ae0a8c3b0d4d0bca19117c23f937da5e886acb635ecc2018453b05816554