Malicious PDF — malware analysis report

Static analysis result for SHA-256 aed776d153542980…

MALICIOUS

PDF

44.9 KB Created: 2020-03-31 00:57:55 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 1d6f36c5b03e72146dc34234400fbb49 SHA-1: 140638f772242ecaf9c011caacc8ab0deb988630 SHA-256: aed776d1535429809bcca0f33825d76587a3f2e38616dacc1825f207c44377d8
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents on different domains. The ML classifier also strongly indicated maliciousness. This suggests the document is part of a link farm or SEO manipulation scheme, potentially used to distribute malware or engage in phishing by directing users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://spiritualresearchnetwork.com/uploads/1/3/0/4/130494871/130494871.html#propiedades+quimicas+germanio
    • http://earlywarninginc.net/uploads/1/3/0/9/130969726/danosutirenun.pdf
    • http://tadbservicesinc.com/uploads/1/3/0/9/130969497/3306598.pdf
    • http://cornerstoneyulee.com/uploads/1/3/0/3/130313854/gikorirosamed.pdf
    • http://ecruos.net/uploads/1/3/0/8/130814873/9840332.pdf
    • http://wearelaura.com/uploads/1/3/0/2/130288545/5319821.pdf
    • http://lasalledumoulinneuf.com/uploads/1/3/0/3/130379051/ferikeda.pdf
    • http://gyrotech.org/uploads/1/3/0/7/130739437/vibutusuraluri.pdf
    • http://edengiftco.com/uploads/1/3/1/4/131438278/ninixusosi.pdf
    • http://voirin-bourgault.com/uploads/1/3/0/2/130272284/341369108.pdf
    • http://brightburnproperties.com/uploads/1/3/0/8/130874370/bakipovajumozum.pdf
    • http://stitchlifetogether.com/uploads/1/3/0/9/130969855/403b7909.pdf
    • http://abundancebirthright.com/uploads/1/3/0/7/130738622/soreb.pdf
    • http://paradoxreptiles.com/uploads/1/3/0/7/130740022/70c0f6e.pdf
    • http://ontarioiguanas.com/uploads/1/3/0/5/130540767/posafunuxamobofijel.pdf
    • http://badbullygame.com/uploads/1/3/1/1/131164027/19e95d0753.pdf
    • http://901parkave.com/uploads/1/3/1/4/131483143/kadorika.pdf
    • http://consciouscollectible.com/uploads/1/3/0/6/130639960/bomokapes_fanepurupize_pewodamobak_jebepazodiki.pdf
    • http://melisaangulo.com/uploads/1/3/0/6/130620783/1b7d7d95aa83.pdf
    • http://superligenergy.com/uploads/1/3/0/3/130313004/zipemo_menawomilumil_lirosivov_mirapomofif.pdf
    • http://pitchtreemetalworks.com/uploads/1/3/0/4/130483238/vowofefuje.pdf
    • http://mohsinhasan.com/uploads/1/3/0/6/130621180/xezepuzewero_dofejirugix_dorozinejirone.pdf
    • http://whatinternswear.com/uploads/1/3/0/4/130435751/fe90af43a41701.pdf
    • http://newbornumc.org/uploads/1/3/0/2/130289429/4588397.pdf
    • http://bshppopup.com/uploads/1/3/0/6/130639283/b28cb0c3a5918.pdf
    • http://hostmaster.aso-organisation.ch/uploads/1/3/0/8/130813804/4891647.pdf
    • http://bshppopup.com/uploads/1/3/0/6/130639283/b28cb0c3a5
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000082f8.bin
bfc8f5fbbcdd826d718db3ff7894db770c0961366d8af91e82d0079346da6308
pdf-font-stream PDF embedded font (sfnt) at offset 0x82F8 9176 bytes