Malicious PDF — malware analysis report

Static analysis result for SHA-256 8934c022eb6c76c5…

MALICIOUS

PDF

48.3 KB Created: 2020-03-29 06:44:57 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2020-09-24
MD5: 4dcab6168f3c1412622872afb875cee8 SHA-1: d30eeb2dabd3e40c37fcc60a4433ac2f884b3075 SHA-256: 8934c022eb6c76c5a45551bd84efc8efac814080e8131191210aecda726f5af4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of embedded external links, forming a link farm. The primary URL points to a page titled 'Limites con factorizacion y racionalizacion', which itself contains numerous links to other PDF files hosted on various domains. This suggests a tactic to distribute malicious content or engage in SEO manipulation, likely as a lure for phishing or other malicious activities. No scripts were extracted, but the PDF structure and embedded links are indicative of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://host37.carmichaelnl.com/uploads/1/3/0/2/130271177/130271177.html#limites+con+factorizacion+y+racionalizacion PDF link annotation
    • http://buygreatweed.com/uploads/1/3/0/3/130379379/5526612.pdfIn PDF document text
    • http://halalthisway.com/uploads/1/3/0/6/130620622/piruzusu.pdfIn PDF document text
    • http://tutoryounsu.net/uploads/1/3/0/3/130379463/3953698.pdfIn PDF document text
    • http://appliedwine.com/uploads/1/3/0/7/130739614/zifagoroma.pdfIn PDF document text
    • http://artisanbathandbody.com/uploads/1/3/1/4/131414240/sekesu-volajov-xazizegi.pdfIn PDF document text
    • http://consultleadership.com/uploads/1/3/0/5/130539843/869cd77f2c.pdfIn PDF document text
    • http://webmail.drawmaton.com/uploads/1/3/0/5/130588663/muvaxobulu.pdfIn PDF document text
    • http://love-in-the-afternoon.com/uploads/1/3/0/6/130620233/xedavu-sotol-lusukedajowoxe-temuzibipup.pdfIn PDF document text
    • http://econogreen.org/uploads/1/3/0/4/130475981/zefejuxadi_wuvesobelavo_wujitow_mitebunezop.pdfIn PDF document text
    • http://angelscenographer.com/uploads/1/3/0/2/130291499/97da250f8155c93.pdfIn PDF document text
    • http://schreiberagserviceinc.com/uploads/1/3/0/5/130590008/2604284.pdfIn PDF document text
    • http://gravelinelandscaping.com/uploads/1/3/0/7/130776250/8943ec39fe2a9.pdfIn PDF document text
    • http://itsforthepeople.com/uploads/1/3/0/7/130739525/folagi.pdfIn PDF document text
    • http://kemafamilyptyltd.com/uploads/1/3/0/6/130639343/piwax_pilomalivijad_jezinuviluxek_kapirifebu.pdfIn PDF document text
    • http://suffolkcountyswimmingpools.com/uploads/1/3/0/9/130969818/kuxef.pdfIn PDF document text
    • http://nammoi.net/uploads/1/3/0/2/130289244/1c841a1d031d2.pdfIn PDF document text
    • http://eldersemporium.com/uploads/1/3/0/3/130379362/61c893e5834052.pdfIn PDF document text
    • http://papadie2uscata.com/uploads/1/3/0/6/130605253/kotilibenuvod-buroforomer-zorojipavis-poniwapibi.pdfIn PDF document text
    • http://isaglobal.org/uploads/1/3/0/6/130621582/kemow.pdfIn PDF document text
    • http://buycialis.com/uploads/1/3/0/8/130814303/39496.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006efb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6EFB 9828 bytes
SHA-256: 47262d5db2683f5c4f78c0618daeb1c32571c3da311b773b396d86dbbed7ac58
font_01_sfnt_off00009294.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9294 2652 bytes
SHA-256: e2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea
font_02_sfnt_off00009bfd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9BFD 16080 bytes
SHA-256: 3e9a9dfb40a01f9f7c9c545b28ba37f1de74591f2b47bc69a9983f40f3f3ebd7