Malicious PDF — malware analysis report

Static analysis result for SHA-256 84706941a7be1317…

MALICIOUS

PDF

84.6 KB Created: 2020-04-08 03:43:19 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 2f7b52483716bfbe74c6c65cbc0bd701 SHA-1: 85d00721b12042340eefe89b47acace192de512e SHA-256: 84706941a7be1317957f913dd54cfb83d166e3fcc4d3983d54ffe1f0be47c4c1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, many of which point to other PDF files hosted on similar domains. The document body, though heavily obfuscated, contains a URL that appears to be a lure for downloading religious texts, which is likely a pretext for distributing malicious content. The ML classifier strongly indicated maliciousness, and the heuristic firings confirm the presence of a link farm designed to host and distribute PDF files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://the-tv-guy.com/uploads/1/3/0/5/130589413/130589413.html#shrimad+bhagwat+geeta+in+bengali+pdf+free+download
    • http://stateoftheblackdollar.net/uploads/1/3/0/8/130813557/sumirok.pdf
    • http://raymondryanray.com/uploads/1/3/0/5/130543050/wefud_pirudosivogenu_galeminokoj.pdf
    • http://ditneyhill.com/uploads/1/3/1/3/131384044/cbf303d44.pdf
    • http://wolfdenwoodshop.com/uploads/1/3/0/7/130776148/nuvijelozobowirum.pdf
    • http://webmail.bestdealvacations.com/uploads/1/3/0/2/130288603/f860e5.pdf
    • http://sappystrees.com/uploads/1/3/0/7/130739778/tuzok.pdf
    • http://petesbat.com/uploads/1/3/0/9/130969953/3370947.pdf
    • http://madotz32.net/uploads/1/3/0/7/130739742/jotebozixak.pdf
    • http://artbookblog.org/uploads/1/3/0/7/130739347/7880b953f41.pdf
    • http://getit.kim/uploads/1/3/0/4/130436306/8204854.pdf
    • http://fedorahosted.org/lohit
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e692.bin
5d6d1115d9154fd9544b4d0c0dd8c0ddb73955a2f938cdaeb2d27edaee185568
pdf-font-stream PDF embedded font (sfnt) at offset 0xE692 7680 bytes
font_01_sfnt_off000104aa.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x104AA 1388 bytes
font_02_sfnt_off00010c10.bin
025d808a4ac2e5747a84bbe3ab6c260123ea940a63d6780f3b1abdc2fd1d7ed1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C10 19784 bytes