Malicious PDF — malware analysis report

Static analysis result for SHA-256 98e2a38e63710b48…

MALICIOUS

PDF

38.4 KB Created: 2020-04-06 03:22:31 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: e0d86c2a1a0ea4238722801ae608b0c7 SHA-1: 082f5d326cc667852dc4bd52d4d8c04460640e58 SHA-256: 98e2a38e63710b48c96d0a7bb3cabd7f3a99ebd968346b6c88a98077e1a7d831
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or SEO spam campaign. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, but the primary malicious activity appears to be the distribution of numerous external links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wehappyhair.com/uploads/1/3/1/4/131438036/131438036.html#generalized+linear+model+vs+multiple+regression
    • http://alexmonastra.com/uploads/1/3/1/0/131070151/sozibeweximez.pdf
    • http://artgallerytrailwnc.org/uploads/1/3/0/2/130289247/7c163d5b58e3d3.pdf
    • http://opaxglobal.com/uploads/1/3/0/7/130775087/davigipomos.pdf
    • http://ashish-jain.me/uploads/1/3/0/3/130323337/gowijomovoso.pdf
    • http://katiesplayhouse.com/uploads/1/3/0/5/130546209/a2dbf8.pdf
    • http://elizg.com/uploads/1/3/0/7/130739975/tipowopelipavi.pdf
    • http://changeofheartmentoring.com/uploads/1/3/0/6/130620937/nefogixujin_jezude.pdf
    • http://thevelvetteddy.com/uploads/1/3/0/5/130539492/4807425.pdf
    • http://graphixline.com/uploads/1/3/1/4/131406273/2081507.pdf
    • http://metastudio.io/uploads/1/3/0/8/130814328/a391b9.pdf
    • http://nonprofit-hr.org/uploads/1/3/0/6/130639744/b98b03d.pdf
    • http://greenifysomalia.org/uploads/1/3/0/6/130604086/kogibiropusesa.pdf
    • http://kardio-privat.com/uploads/1/3/1/3/131398225/nolite-tuzobozifilip-rapukega.pdf
    • http://therocketdog.net/uploads/1/3/0/7/130775174/noxiru.pdf
    • http://kikolett.com/uploads/1/3/1/4/131453179/9026441.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000068c7.bin
ee862432ce58f3b9e2e4f2dbb4f11962e5a9a15f1386ce55eab404515d3d2e06
pdf-font-stream PDF embedded font (sfnt) at offset 0x68C7 8796 bytes