Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6a9b9cc971adcc0…

MALICIOUS

PDF

43.2 KB Created: 2020-06-23 02:14:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e808a46e85fd277ab2c97d3a2634fcb8 SHA-1: d99d5206ed67259652ef33faa9a620fd47170a2e SHA-256: a6a9b9cc971adcc04d4fae99db447072dad8249ef885b72abcd8b2269cdf69e7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links to various domains, a technique commonly used for SEO spam or to redirect users to malicious content. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains references to 'Acme 6001 juicer manual' and URLs that appear to be part of a link farm, suggesting a lure to drive traffic to potentially compromised or malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://angelicartshop.com/uploads/1/3/0/7/130739894/130739894.html#acme+6001+juicer+manual
    • http://christydelfresno.com/uploads/1/3/0/4/130488969/mazokasegukif.pdf
    • http://mrsandonian.com/uploads/1/3/0/4/130483238/wopipawujuxif_makilubiguja.pdf
    • http://shadydjw.com/uploads/1/3/0/3/130313786/8775973.pdf
    • http://alphalove.com/uploads/1/3/0/4/130483926/xokozasone.pdf
    • http://lionpro.fr/uploads/1/3/1/8/131871488/terud.pdf
    • http://mta-sts.mx20.eigen-wijze.com/uploads/1/3/2/3/132302992/rupaxopu_dobotudabim_pusoto.pdf
    • http://bilingualkiddos.com/uploads/1/3/0/8/130815124/tomomeguper.pdf
    • http://theaveragejose.ca/uploads/1/3/1/8/131872055/15c86785ac7f633.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b48.bin
523ee49ca047c9770de6b538943f8ba34f6719e885c453086795ef5d6c08d61a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B48 4872 bytes
font_01_sfnt_off00007baf.bin
50319cafe2cdc35fc48d9637c82f85bedcd6898acfa8230069b5fa61cf7c2175
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BAF 11120 bytes