Malicious PDF — malware analysis report

Static analysis result for SHA-256 bcb06f48b85ef9f6…

MALICIOUS

PDF

35.7 KB Created: 2020-03-28 09:06:42 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: f7735a7abbbb8fafec79b466ec17ecce SHA-1: d470f1ef260240688d070148c150449eac14a9ea SHA-256: bcb06f48b85ef9f6f48e7a3e727869c9ea317c49c73a4508552f1c516824d855
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The ML_NYX_PDF_MALICIOUS heuristic also flagged this file with high confidence. The embedded URLs suggest a link farm or SEO poisoning tactic, likely intended to direct users to malicious content or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://elizabethsummerseq.com/uploads/1/3/0/8/130815059/130815059.html#%28ch3%293ch+line+structure
    • http://atheart.us/uploads/1/3/0/2/130272385/sekutonalesep.pdf
    • http://www.realfoodrd.org/uploads/1/3/0/3/130323362/babom-venotifoxo-xopudirokeji-gubopimivawila.pdf
    • http://passivewealthpartners.com/uploads/1/3/0/8/130814526/wikupawusige_mekodibemuvi.pdf
    • http://www.eaincense.com/uploads/1/3/0/6/130639734/8902382.pdf
    • http://localhomenyc.com/uploads/1/3/0/5/130588261/fupuxisasedetip.pdf
    • http://shorebreaksurfproducts.com/uploads/1/3/0/7/130738652/ragoxab-melovifa.pdf
    • http://abbygmua.com/uploads/1/3/0/8/130874169/giguban.pdf
    • http://elpacifico2hoa.com/uploads/1/3/0/4/130477278/nesazofexox-muximodudir-fegatuda.pdf
    • http://blehmeninpain.com/uploads/1/3/0/6/130639781/858cd2b.pdf
    • http://www.synthetic-cannabinoid-cathinone-fentanyl-training.com/uploads/1/3/0/5/130538949/a1c673127550022.pdf
    • http://mybellaboop.com/uploads/1/3/0/7/130738680/xexojazuwirawobibep.pdf
    • http://code-camp.ru/uploads/1/3/0/6/130621805/zisekodomatutoz.pdf
    • http://buffalopayroll.com/uploads/1/3/0/4/130483110/360962.pdf
    • http://kamloopswritersfestival.com/uploads/1/3/0/4/130476065/kuvovexo.pdf
    • http://www.belcantoflutist.com/uploads/1/3/0/5/130551700/gazozovozon-fatej-jirun.pdf
    • http://youngwomenestablishments.com/uploads/1/3/0/8/130813554/sakixexig.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000056d9.bin
373639af3a8937e6fd88fe995198a2fec48690c6fd8dff7b1d8fb901257d8182
pdf-font-stream PDF embedded font (sfnt) at offset 0x56D9 7068 bytes
font_01_sfnt_off000072c6.bin
885781ec91db75dc8c4a6a3d3dac0324bdfdb8f2239dab70466c62035ae072da
pdf-font-stream PDF embedded font (sfnt) at offset 0x72C6 4144 bytes