Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e885ceef444b0cf…

MALICIOUS

PDF

68.8 KB Created: 2021-03-07 23:19:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 19d35587d23de7b339f54f66133a77ea SHA-1: 717b1aacbaffc30a4a892be54f35063d9ab0f708 SHA-256: 9e885ceef444b0cf6d853bee77c3ff6b14f5d9455a6dd10cf79b87d5df087632
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are part of a link farm designed to manipulate search engine results. The primary URL, https://midufefew.ru/wix?keyword=simplifying+polynomials+worksheet+doc, suggests a lure related to educational content to drive traffic to malicious sites. The ML classifier strongly indicated maliciousness, and the presence of many external links points towards SEO spam or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=simplifying+polynomials+worksheet+doc
    • http://world-wildshop.com/26209238981rli96.pdf
    • http://vamoktin.ru/jesujisufrbtuj.pdf
    • http://zaralutodunuwa.66ghz.com/systems_of_equations_elimination_method_worksheet.pdf
    • https://modulofironufi.weebly.com/uploads/1/3/4/4/134402713/7670062.pdf
    • http://nevoxodaw.66ghz.com/bullet_force_hack_apk_obb.pdf
    • http://itgermany.net/fundamentos_del_voleibol_remate_y_bloqueove4n9.pdf
    • https://gunobapeve.weebly.com/uploads/1/3/4/7/134706327/mogujikobe_wejav.pdf
    • https://zokukomusisitu.weebly.com/uploads/1/3/5/3/135323242/fakuladesi.pdf
    • https://tunizobun.weebly.com/uploads/1/3/1/0/131069832/dipifokepimikomave.pdf
    • http://sipezolenanuwep.22web.org/first_alert_brk_7010b_hardwired_smoke_detector_with_photoelectric_sensor_and_battery_backup.pdf
    • http://useporte.xyz/62488182114dnhol.pdf
    • https://letotanuvimipe.weebly.com/uploads/1/3/4/5/134598603/8354a.pdf
    • http://difijeso.iblogger.org/is_wheel_of_time_good.pdf
    • http://zavupefedeba.22web.org/beautiful_creatures_soundtrack.pdf
    • https://welabelodaset.weebly.com/uploads/1/3/5/3/135399274/a5ee0cb27f222f3.pdf
    • http://bamasadukarudam.iblogger.org/45407332333.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gubitubitaxe.rf.gd/33633052603.pdf
    • http://juvogexef.rf.gd/how_big_is_a_route_44_from_sonic.pdf
    • http://nopetavu.rf.gd/betojo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ca3e.bin
c89a597fb1447009aeb3dcd0112571a92157ab8440335e624e602ccc7399d130
pdf-font-stream PDF embedded font (sfnt) at offset 0xCA3E 5932 bytes
font_01_sfnt_off0000de60.bin
ac58c2d67c72eeb5908250876d62cf4e368f04b6cdb7271606fc43be38e7bca7
pdf-font-stream PDF embedded font (sfnt) at offset 0xDE60 11568 bytes