Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b4d0e4d293a142c…

MALICIOUS

PDF

33.4 KB Created: 2020-05-21 22:22:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2020-09-24
MD5: 6906fbc41c398dd001bdc11317444311 SHA-1: c82331a30cdb2a7f738ead014c71905086e76653 SHA-256: 8b4d0e4d293a142c1b7304f00ac566082c0bc1836eb48087f8ebeb68b0ebb7cd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF document contains a large number of external links, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, with 'c2cigars.com' being a dominant host. While no scripts were extracted, the sheer volume of outbound links suggests a malicious intent to redirect users to potentially harmful sites. The document body contains garbled text and metadata, but the presence of URLs is the primary indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://openboxsaving.com/uploads/1/3/1/4/131408528/131408528.html#bead+loom+patterns+simple PDF link annotation
    • http://c2cigars.com/uploads/1/3/1/1/131164077/jezedu.pdfIn PDF document text
    • http://hollywoodcalling.ca/uploads/1/3/1/3/131380345/8997135.pdfIn PDF document text
    • http://iecsae.com/uploads/1/3/0/5/130550813/rufokajuraforimefi.pdfIn PDF document text
    • http://bmajorevents.net/uploads/1/3/1/4/131437677/vuliwepalimupag_faxafileteminor_zimizoxo.pdfIn PDF document text
    • http://valueaddexpert.com/uploads/1/3/1/4/131438784/3516448.pdfIn PDF document text
    • http://kellymford.com/uploads/1/3/0/6/130639626/15ca4c2649b5098.pdfIn PDF document text
    • http://deifadalvi.com/uploads/1/3/0/6/130604706/tuvopoko.pdfIn PDF document text
    • http://artvisionstudios.com/uploads/1/3/0/2/130272638/8871245.pdfIn PDF document text
    • http://greenthumbgardening.info/uploads/1/3/1/3/131379421/finatus_bekewo_nisidejotunex_tixatinigelo.pdfIn PDF document text
    • http://arete-managementsolutions.com/uploads/1/3/1/6/131606511/rugunafasuwerepa.pdfIn PDF document text
    • http://imforked.com/uploads/1/3/1/8/131858044/1fca4575762.pdfIn PDF document text
    • http://theglutegrinder.org/uploads/1/3/0/6/130639856/resixivirodabef.pdfIn PDF document text
    • http://basslakebullfrogs.com/uploads/1/3/0/5/130542971/venomigodevami.pdfIn PDF document text
    • http://westshoreland.net/uploads/1/3/1/0/131069838/semikov.pdfIn PDF document text
    • http://dawgonline.com/uploads/1/3/0/2/130273748/08ecd6582817c03.pdfIn PDF document text
    • http://infinitestudiollc.com/uploads/1/3/0/2/130272804/3744885.pdfIn PDF document text
    • http://sweetdaisydesigns.com/uploads/1/3/0/8/130814296/luvujobogegutam.pdfIn PDF document text
    • http://neverbetterfishingcharters.com/uploads/1/3/1/1/131164012/libin_ditotetomom.pdfIn PDF document text
    • http://perisedighlaw.com/uploads/1/3/0/5/130588895/jurasojewo_sipatazase.pdfIn PDF document text
    • http://globalsolarinnovations.info/uploads/1/3/1/4/131406892/tefanovekawakikus.pdfIn PDF document text
    • http://1200southmadison.com/uploads/1/3/1/4/131453329/2659468.pdfIn PDF document text
    • http://stiknstop.com/uploads/1/3/0/7/130738963/wonij-dofexol.pdfIn PDF document text
    • http://biontplus.com/uploads/1/3/0/3/130323161/rexuki.pdfIn PDF document text
    • http://mirodynamics.com/uploads/1/3/0/7/130775485/neguxo.pdfIn PDF document text
    • http://strongheartpowerteam.com/uploads/1/3/1/0/131070080/xafunalu_sanufetix_mujamodilib_tapib.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005835.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5835 9784 bytes
SHA-256: 665ada67f4741720410bbe18fcccdb2c07789481be705e1b0904cb428e5e6205