Malicious PDF — malware analysis report

Static analysis result for SHA-256 94b09d3de2b556c5…

MALICIOUS

PDF

40.1 KB Created: 2020-03-26 08:58:21 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 2b57c012a2df36b68956a2f19feca022 SHA-1: 002a28b9ec19f93ac9a8dfec7c41fbb7bd8aaed0 SHA-256: 94b09d3de2b556c5f6074d53dc5142e7b0231fb6f58d70ebc3fb526d77ae0581
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains a large number of external links, suggesting a link farm or redirection strategy. The ML classifier strongly indicated maliciousness. The primary attack pattern involves directing users to a multitude of external PDF files hosted on various domains, likely as a means to distribute further malicious content or engage in SEO abuse for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mainelectricalsolutions.ca/uploads/1/3/0/5/130588545/130588545.html#presente+progresivo+estructura+afirmativa
    • http://tribecamobile.com/uploads/1/3/0/6/130604820/5c0853ecdb652.pdf
    • http://allforkidsboutique.com/uploads/1/3/1/1/131164293/vutonabori-labakepiburowe-gegubatixopode.pdf
    • http://londyn.letenky-sky.sk/uploads/1/3/0/8/130815080/kutovaxeravow.pdf
    • http://parksidemanorcondo.com/uploads/1/3/0/5/130545365/6740736.pdf
    • http://vzlasurfspotcom.net/uploads/1/3/0/8/130814784/nebalu.pdf
    • http://preview.simonetteberry.com/uploads/1/3/0/6/130620314/zobeguv.pdf
    • http://mihiomanus.com/uploads/1/3/0/5/130539735/8dc512c18e7c.pdf
    • http://unconditionalloveseminar.com/uploads/1/3/0/4/130488332/8745657.pdf
    • http://webmail.geekendcast.com/uploads/1/3/0/7/130776371/3550842.pdf
    • http://monkeypay.net/uploads/1/3/0/9/130969561/kederifiriwivabab.pdf
    • http://wmbc2.com/uploads/1/3/0/5/130588639/1046834.pdf
    • http://tulumba.ch/uploads/1/3/0/5/130544781/6034611.pdf
    • http://greendaysfarm.com/uploads/1/3/0/5/130541443/nirorusotazoxa.pdf
    • http://the-city-exchange.com/uploads/1/3/0/5/130588686/6915521.pdf
    • http://webmaster.windskulpturen.com/uploads/1/3/0/7/130738646/gosivinafupanur.pdf
    • http://mta-sts.mx.olol-church.com/uploads/1/3/0/8/130814178/d443c4324d7c.pdf
    • http://charitywp.com/uploads/1/3/0/8/130874564/dodowo_nufewin_wijivinape_govivokuves.pdf
    • http://www.houstonhaircompany.com/uploads/1/3/0/8/130874058/pivobag_bosubu_wixojanavuzamot.pdf
    • http://appalachianbreastfeedingservices.com/uploads/1/3/0/7/130739889/xudevizodeki.pdf
    • http://growoutreach.org/uploads/1/3/0/5/130589285/tevukugukepo-jodiwuferi-wotusedetegupef.pdf
    • http://michigantalks.net/uploads/1/3/0/5/130543170/xitisuruvobago.pdf
    • http://projetologistics.com/uploads/1/3/0/2/130272442/siraleduropupu.pdf
    • http://moderntabletoprva.store/uploads/1/3/0/5/130547078/c40e2a48.pdf
    • http://lonestarservicecompany.com/uploads/1/3/0/5/130546118/figudifipedebusanim.pdf
    • http://moderntabletoprva.store/uploads/1
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073a0.bin
ef7354f6ba4cd8318bd4a5db60e8becd3855dac1438e23c20a0771f57557e46e
pdf-font-stream PDF embedded font (sfnt) at offset 0x73A0 8376 bytes