Malicious PDF — malware analysis report

Static analysis result for SHA-256 91a9955610cb93c2…

MALICIOUS

PDF

51.7 KB Created: 2020-06-10 11:17:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: df10fa9639136616b8bf6138987e51b3 SHA-1: 8b24adea20022069760f5525f5c2433eda6611cd SHA-256: 91a9955610cb93c2319d9b82ab963382c4d011995a42ef7716e5fa2f8b5996ae
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF document is identified as malicious by an ML classifier with high confidence. It contains a large number of external links, many of which point to other PDF files hosted on various domains, suggesting a link farm or SEO manipulation tactic. The document body, though partially corrupted, indicates a lure related to a 'Honda Odyssey 2008 manual en español'. The presence of numerous external PDF links is a strong indicator of malicious intent, likely to distribute malware or engage in phishing. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wehappyhair.com/uploads/1/3/0/7/130775796/130775796.html#honda+odyssey+2008+manual+en+espa%25C3%25B1ol
    • http://mta-sts.mail.natureimprintedphotography.com/uploads/1/3/0/7/130739129/zixaweviguvuzupuxepi.pdf
    • http://k3oil.com/uploads/1/3/0/8/130874292/015af18464ef.pdf
    • http://bachatainlosangeles.com/uploads/1/3/0/3/130313345/9949520.pdf
    • http://themelineevents.com.au/uploads/1/3/0/5/130551607/mufisibasokubo_kilevonefo.pdf
    • http://bsquarellc.com/uploads/1/3/0/4/130435781/moworuwog.pdf
    • http://blackskyconsulting.net/uploads/1/3/0/2/130273738/radaxodorexab.pdf
    • http://scorpiolegion.site/uploads/1/3/0/7/130739450/98ae5bef4e91.pdf
    • https://nalusekixij.files.wordpress.com/2020/06/82670458716.pdf
    • https://nigadimuzifo.files.wordpress.com/2020/06/votupidakaxalume.pdf
    • https://wesegakivur.files.wordpress.com/2020/06/rawik.pdf
    • https://sirudamulax.files.wordpress.com/2020/06/vurigujukusutofi.pdf
    • https://suwemolu.files.wordpress.com/2020/06/27710080440.pdf
    • https://xavizatilem439575075.files.wordpress.com/2020/06/84550324074.pdf
    • https://jumitedav.files.wordpress.com/2020/06/jinolukiwidanixuvoki.pdf
    • https://fububoxoludi.files.wordpress.com/2020/06/57635497726.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000085b7.bin
0f9e641c2a99e432d96574214e4ae70e279c5a15ecdfadc895a8c6fa5ac9b03e
pdf-font-stream PDF embedded font (sfnt) at offset 0x85B7 11564 bytes
font_01_sfnt_off0000abf7.bin
4ef9506ee11a349461550e6b437e3786686b598308a87786035880d16624999d
pdf-font-stream PDF embedded font (sfnt) at offset 0xABF7 16060 bytes