Malicious PDF — malware analysis report

Static analysis result for SHA-256 b80c80f4017707a4…

MALICIOUS

PDF

30.0 KB Created: 2020-03-14 23:55:41 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d81a39f9562cae6c26da9b30a33fea9b SHA-1: 7aa2cb3b4d79098ac1a495381b7eddeecf9a0ec0 SHA-256: b80c80f4017707a4cabf0f6d3917753991ea11f3ff7e29841fb22b372cc30da6
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The ML classifier also strongly indicated maliciousness. The primary attack pattern involves directing users to these external URLs, which are likely used for SEO manipulation or to host further malicious content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nobubarcelona-emea-es.devsite-1.com/uploads/1/3/0/4/130489131/130489131.html#django+template+extends+base+html
    • http://brothersnblue.com/uploads/1/3/0/4/130483489/ragopolavebasewike.pdf
    • http://www.atladdictions.com/uploads/1/3/0/8/130814297/6a51ee0.pdf
    • http://valleychemicalcompany.com/uploads/1/3/0/4/130488301/9883284.pdf
    • http://cpanel.josephhudson.com/uploads/1/3/0/7/130739153/duxuduwaderupupo.pdf
    • http://peterandannemariehelms.com/uploads/1/3/0/5/130542875/445b7729.pdf
    • http://autoturnrevit.transoftsolutions.com/uploads/1/3/0/6/130604804/4d34a.pdf
    • http://alternativesassessment.org/uploads/1/3/0/6/130605255/5902990.pdf
    • http://puresolutionslife.com/uploads/1/3/0/6/130605279/xinavedo.pdf
    • http://hacannabis.com/uploads/1/3/0/2/130287735/ranosemizubibawi.pdf
    • http://caddycapdesigns.com/uploads/1/3/0/7/130740266/mizezumunet.pdf
    • http://fantasyalmanac.com/uploads/1/3/0/4/130488476/bodipata_lisibesaz_julot.pdf
    • http://jayblkmgc.com/uploads/1/3/0/8/130813800/sevisuzedipako.pdf
    • http://ok-lendava.si/uploads/1/3/0/6/130604125/4f4e36b59b0.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000050b9.bin
755b237867a22a85f4e4951d2c8d18a51eceecfec490f5bae5e44f6a8e3d810f
pdf-font-stream PDF embedded font (sfnt) at offset 0x50B9 6616 bytes