Malicious PDF — malware analysis report

Static analysis result for SHA-256 a08aea07ff455b36…

MALICIOUS

PDF

95.2 KB Created: 2020-03-12 08:30:27 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: fbc4c2bdbeb9a6bfd89ca08a8792bdfe SHA-1: 733d3db4cda1a3f6f1ee212de19bd623fcaa6529 SHA-256: a08aea07ff455b36922166fee029af10e402e6928cdfa22e342a1ff89a9c88cd
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or SEO manipulation tactic. The ML classifier also strongly indicated maliciousness. The embedded URLs are likely used to redirect users to malicious content or further stages of an attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fly5c.bpmtc.com/uploads/1/3/0/8/130874160/130874160.html#can+i+translate+chinese+symbols+into+english
    • http://detoxspray.net/uploads/1/3/0/5/130550936/bebusarikipuwudovo.pdf
    • http://www.sneaker-rent.co.uk/uploads/1/3/0/6/130604672/waguxowuwaxiri.pdf
    • http://myvrcpp.com/uploads/1/3/0/7/130776518/lewirobevizojo.pdf
    • http://dirtysoles305.com/uploads/1/3/0/4/130476766/777119.pdf
    • http://nathanielrichguitars.com/uploads/1/3/0/8/130874129/siwaxege_wujofiwopegoner.pdf
    • http://fastblueprints.com/uploads/1/3/0/4/130476447/395661.pdf
    • http://www.caktibalitrans.com/uploads/1/3/0/6/130639770/6b10783c3eff24.pdf
    • http://leaderkast.com/uploads/1/3/0/6/130639166/ruberusiporavunawu.pdf
    • http://drdeborahbarbiere.com/uploads/1/3/0/5/130545447/merobuline.pdf
    • http://bluffcitybees.com/uploads/1/3/0/3/130323967/xipifiwobatona-lokevojutisi-xovimapimuma-basuviz.pdf
    • http://756.bpmtc.com/uploads/1/3/0/6/130603737/fuxonavanafor.pdf
    • http://power101jamz.net/uploads/1/3/0/5/130588445/gisudozezu.pdf
    • http://rickyzheng.net/uploads/1/3/0/8/130873818/a8a9e2.pdf
    • http://grapescore.com/uploads/1/3/0/4/130489143/popanuri.pdf
    • http://clean-tea.com/uploads/1/3/0/7/130776577/tipurukakejere-zivamaw-zubixolerulizil.pdf
    • http://rgbfilmindustri.com/uploads/1/3/0/6/130620996/c5deb96c4b.pdf
    • http://mail.longislandnailtech.com/uploads/1/3/0/4/130476816/8777252.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c66c.bin
632b0e85098197d9d68fb78889867a40229058f19686f0c53704810e5d0ee152
pdf-font-stream PDF embedded font (sfnt) at offset 0xC66C 9908 bytes
font_01_sfnt_off0000e7ef.bin
26b07920bdb2af0c9bcfc7d19823594e23264e39e070a1709f66a5a31f8ff942
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7EF 36496 bytes
font_02_sfnt_off00015765.bin
619d2006ca8b9e75dc0d1bd49cc71f826634f8cc7ea0f16fcd27643bd1165791
pdf-font-stream PDF embedded font (sfnt) at offset 0x15765 16520 bytes