Malicious PDF — malware analysis report

Static analysis result for SHA-256 94247089c4785972…

MALICIOUS

PDF

46.7 KB Created: 2020-03-29 23:20:33 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ed15c1dd4e6192e982ebfb10793eb506 SHA-1: 716d13a16562e3a95877489eb738afb6f35d3fb7 SHA-256: 94247089c478597207833bb13954d4e66f698c4e3acca10a3d0ab590294c3df4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous external links, a common tactic for SEO spam or phishing campaigns. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains text related to regulations and URLs, reinforcing the idea that the document's purpose is to redirect users to potentially malicious external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://radissonbluhotelkigali.devsite-1.com/uploads/1/3/0/8/130874586/130874586.html#regulations+for+assisted+living+facilities+in+virginia
    • http://jhpconstruction.org/uploads/1/3/0/4/130476471/aef0995de13.pdf
    • http://agostinodeangelis.com/uploads/1/3/0/6/130639808/896129.pdf
    • http://second-stepconsulting.com/uploads/1/3/0/7/130775244/nidamebefib_lutujenilifiwez.pdf
    • http://missteendreamusa.com/uploads/1/3/0/5/130589007/03680b4efd.pdf
    • http://clearviewrentalproperties.com/uploads/1/3/0/7/130776405/xilufozon.pdf
    • http://hydrologyskincare.net/uploads/1/3/0/8/130814914/rorikusik_daginakanazu_natiru.pdf
    • http://emeraldgreenandwhite.com/uploads/1/3/0/4/130488539/8361282.pdf
    • http://questionata.net/uploads/1/3/0/5/130550901/vapajuwesovegukub.pdf
    • http://californiaspiritscompany.com/uploads/1/3/0/4/130489800/9426502.pdf
    • http://escuelaanimalia.com/uploads/1/3/0/8/130874237/fizubimitiratuv.pdf
    • http://grenadabla.org/uploads/1/3/0/2/130289722/vojexuxawekebamezun.pdf
    • http://jgtorresenterprises.com/uploads/1/3/0/8/130874504/wigikelam-gekomike-nimapulazamumov-livoxosesagox.pdf
    • http://cordiallyinvited-designs.com/uploads/1/3/0/6/130621376/litebafejatikobep.pdf
    • http://justgetstrong.com/uploads/1/3/0/4/130483638/dubefonar_xomanoruninuv.pdf
    • http://viewourbenefits.com/uploads/1/3/1/4/131407691/2782806.pdf
    • http://wallmaven.com/uploads/1/3/0/5/130589216/jojisifetal.pdf
    • http://cowboychristmasapp.com/uploads/1/3/0/5/130550663/faa92.pdf
    • http://ask4jay.com/uploads/1/3/1/1/131164249/nekivolavam.pdf
    • http://seatoskycheer.com/uploads/1/3/0/7/130739816/ponokotekevafe_sidut_diwomugap.pdf
    • http://robber-robert.com/uploads/1/3/1/0/131070829/747948.pdf
    • http://saranimation.com/uploads/1/3/0/6/130639583/1bfdc635cd6.pdf
    • http://methylationassociation.org/uploads/1/3/0/6/130639495/3441736.pdf
    • http://wawaunderwraps.com/uploads/1/3/0/5/130540211/laleminuz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008be0.bin
b68851162b2c17cb16545634f958127a0780c81f2f841f9fd68c8ab5dc603d5a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BE0 7972 bytes