Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd4058d55c4e2ca2…

MALICIOUS

PDF

40.9 KB Created: 2020-03-22 09:10:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ebd9113de899e0a4f57e8a932dde79f4 SHA-1: 898c5852e27686b77c6910cbdefb1eb9c5b58958 SHA-256: bd4058d55c4e2ca28b7752958b14ba219a77e70138df288c666ded5ecf03aba8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, characteristic of a link farm designed to manipulate search engine rankings or distribute malicious content. The ML classifier strongly indicated maliciousness. The document body contains text related to a 'Honda karcher pressure washer 2500', likely a lure to entice users to click on the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://andresexpres.com/uploads/1/3/0/6/130603769/130603769.html#honda+karcher+pressure+washer+2500
    • http://www.cj6ek.com/uploads/1/3/0/4/130483745/dofotupimuji-bosibaleb.pdf
    • http://hostmaster.creativityindementiacare.com/uploads/1/3/0/6/130639634/4348869.pdf
    • http://paragonhunter.com/uploads/1/3/0/2/130273850/paxetewikozujiv_xonaputog_linufu_guniwuke.pdf
    • http://thermaledu.org/uploads/1/3/0/6/130621641/ledoludevosen-sevakijumeza-pofadone-jelazubuka.pdf
    • http://motherpuckerscookies.com/uploads/1/3/0/7/130776558/lokepikuwaxowi.pdf
    • http://goliethic.com/uploads/1/3/0/5/130550703/3d37790.pdf
    • http://simplycorkie.com/uploads/1/3/0/8/130874396/mipalupedezudatupozo.pdf
    • http://www.heartrhythmmeditation.com/uploads/1/3/0/6/130639471/5207495.pdf
    • http://mmm.local.stockmi.com/uploads/1/3/0/2/130288416/wasesot.pdf
    • http://fremergrupo.com/uploads/1/3/0/8/130874513/b16067f4ca30f91.pdf
    • http://onpointelectricians.com/uploads/1/3/0/7/130775952/405f5e6f3e.pdf
    • http://lizaladybug.com/uploads/1/3/0/6/130604688/lifujimob_vurepafopajo.pdf
    • http://mytriplec-boutique.com/uploads/1/3/0/2/130289353/dafikojel.pdf
    • http://mx.kimberlyscreativecanvas.com/uploads/1/3/0/2/130270963/nevivizabelikijevaro.pdf
    • http://daviscrossfield.com/uploads/1/3/0/6/130621083/190658.pdf
    • http://norshus.com/uploads/1/3/0/8/130814407/56a1415f2162.pdf
    • http://o2smallhouse.com/uploads/1/3/0/8/130873986/e2bb9.pdf
    • http://developmilwaukee.com/uploads/1/3/0/9/130969566/mipusa_degopagiliz_nupuvivaseko.pdf
    • http://sessionninephotography.com/uploads/1/3/0/7/130738786/9791183.pdf
    • http://www.donaldamorganasc.com/uploads/1/3/0/4/130476605/xaguju-fikifejutomi-favizegedaguge.pdf
    • http://lincolnbailbonds.net/uploads/1/3/0/8/130813855/1386031.pdf
    • http://e-proger.site/uploads/1/3/0/5/130541140/a8c7dc98893.pdf
    • http://angel-magic.com/uploads/1/3/0/8/130873824/fovunesekoves.pdf
    • http://promisemedicalfamilypractice.com/uploads/1/3/0/5/130546209/newudiziraji_lekup_saworilir_zufotupimemes.pdf
    • http://developmilwaukee.com/uploads/1/3/0/9/130969566/mipusa_degopagil
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007808.bin
15bc4a78f0f19fc94c96b33775c16501108da97eede116435f1149e54b846a55
pdf-font-stream PDF embedded font (sfnt) at offset 0x7808 7532 bytes