Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b26d708d7a60995…

MALICIOUS

PDF

46.4 KB Created: 2020-05-01 09:13:59 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: f49dc19934360482b849e91f203ccc3c SHA-1: 812f52a41161b4ea9da2ecb7c6938a48ff93a513 SHA-256: 8b26d708d7a6099557ea6e7c6b3d8e9bcad538f34ec2a0daf84cd561daf71edb
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links to other PDF files hosted on various domains, indicating a link farm or SEO spamming operation. The ML classifier strongly flagged this PDF as malicious. The presence of numerous URLs suggests an attempt to distribute content or redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://avidaenglish.com/uploads/1/3/0/5/130590661/130590661.html#cyclops+shoujo+saipu+anime
    • http://apres33.com/uploads/1/3/1/0/131070195/4752237.pdf
    • http://oregonictonic.biz/uploads/1/3/0/4/130436154/4140ac.pdf
    • http://cafedesquipulas.com/uploads/1/3/0/4/130435706/2175684.pdf
    • http://marketingtouchscreen.com/uploads/1/3/1/3/131380470/tebutimi_xojel.pdf
    • http://passiondetail.net/uploads/1/3/0/5/130588787/vukevota-pekupilojataz-taxebibutoligo-nupeludotinebi.pdf
    • http://gameosphere.com/uploads/1/3/0/7/130738527/xufenigojidawogori.pdf
    • http://callistaclarizia.com/uploads/1/3/0/7/130739103/xenoludolivuxofanu.pdf
    • http://musclegear-asia.com/uploads/1/3/0/5/130539516/030c95e608.pdf
    • http://citywildpdx.com/uploads/1/3/0/7/130776356/4c7bb4a220c.pdf
    • http://fimailbox.com/uploads/1/3/1/4/131438448/360981.pdf
    • http://catsassfashion.com/uploads/1/3/1/4/131453520/9178440.pdf
    • http://fraudandcorruptionasiasummit.com/uploads/1/3/0/6/130640042/kubopedezapevi.pdf
    • http://mariagarcesdaycare.com/uploads/1/3/0/9/130969082/2381201.pdf
    • http://planyour.today/uploads/1/3/0/7/130775304/55138bc92ff65.pdf
    • http://mlpartstudio.com/uploads/1/3/0/6/130639538/sewed-pariwodepinilaj.pdf
    • http://smartdogcom.com/uploads/1/3/0/7/130776023/latufani.pdf
    • http://lewishamcampaigner.com/uploads/1/3/1/4/131407138/2467514.pdf
    • http://devipsita.info/uploads/1/3/1/4/131438163/982804.pdf
    • http://dartplayersmiddleeast.com/uploads/1/3/0/7/130739994/4453128.pdf
    • http://scubaplustours.com/uploads/1/3/0/7/130776730/netolux.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000664e.bin
ff341223d2df56a8c70ed64a6ffeba780c064d6c0cf3842a8137732e67c5db78
pdf-font-stream PDF embedded font (sfnt) at offset 0x664E 7900 bytes
font_01_sfnt_off00008482.bin
db3e60236d3a88d7de5c6e0d1741e1b28fd94a7200d54fa178ef924df9392618
pdf-font-stream PDF embedded font (sfnt) at offset 0x8482 11976 bytes