Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca9250ca086fd93a…

MALICIOUS

PDF

109.2 KB Created: 2020-03-13 02:02:12 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: c4a41d7953e78a9c57a1be976f9d909b SHA-1: ff70166cf60d5b04916c8ea5efa7f4de83ababb4 SHA-256: ca9250ca086fd93a08d19b8ad297cafc0dd043a7eb34c2164a131d86c85a9755
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was flagged by a machine learning classifier with high confidence. It contains a large number of external links, many of which are dynamically generated and point to various domains, suggesting a link farm or SEO spam campaign. One of the extracted URLs is http://lw8bn.bpmtc.com/uploads/1/3/0/4/130488229/130488229.html#urine+chlamydia+trachomatis+rrna+%28pcr%2Fnaat%29, which appears to be part of a lure. The primary attack pattern involves redirecting users to these external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lw8bn.bpmtc.com/uploads/1/3/0/4/130488229/130488229.html#urine+chlamydia+trachomatis+rrna+%28pcr%2Fnaat%29
    • http://fitnessbyalisharenae.com/uploads/1/3/0/6/130604445/saximozuxamibarugila.pdf
    • http://www.gracefuloctopus.com/uploads/1/3/0/6/130640125/685389.pdf
    • http://hshaikhart.com/uploads/1/3/0/4/130435763/2525521.pdf
    • http://demothewriter.com/uploads/1/3/0/5/130538880/sorupikalojesanuxo.pdf
    • http://www.dovernewlife.com/uploads/1/3/0/7/130738874/wiludezufedukil-rubovageb-doxopepefa.pdf
    • http://techeducation.ca/uploads/1/3/0/2/130291996/cb7c2eff.pdf
    • http://spectacularvintageevents.com/uploads/1/3/0/7/130775743/13bbfcd8e26.pdf
    • http://mta142.qualitynow.net/uploads/1/3/0/9/130969249/7608953.pdf
    • http://factofevolution.net/uploads/1/3/0/4/130436252/zikowik.pdf
    • http://stmargaretbiglake.com/uploads/1/3/0/7/130775368/2671648.pdf
    • http://daleanimalhospital.preview.pethealthnetworkpro.com/uploads/1/3/0/5/130588403/zobafirobelemibixof.pdf
    • http://comercializadoraibsasa.com/uploads/1/3/0/8/130874615/5472359.pdf
    • http://bonneicho.com/uploads/1/3/0/4/130488542/mumesadapubepezur.pdf
    • http://www.residentialone.ca/uploads/1/3/0/7/130738708/rekivo.pdf
    • http://holeinonesotogrande.com/uploads/1/3/0/7/130775572/wajusolizip-dawoge-xapugaj.pdf
    • http://webdisk.vandersystreefarm.com/uploads/1/3/0/8/130874154/narufadomirawapudiji.pdf
    • http://circularprice.com/uploads/1/3/0/3/130379101/bojovas.pdf
    • http://hodline.news/uploads/1/3/0/6/130621486/ec41ec97b7dc8f.pdf
    • http://freeyourmindnow.org/uploads/1/3/0/6/130620475/2723240.pdf
    • http://michaelgrew.net/uploads/1/3/0/6/130621790/guzidemalafu.pdf
    • http://dripdropmedspa.com/uploads/1/3/0/5/130551749/roxujika.pdf
    • http://www.whidbeycooks.org/uploads/1/3/0/7/130739001/6706446.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017c26.bin
581b8df8cd035a692af48511d6016979698d50a8c193026cfe3c1cfba02cad92
pdf-font-stream PDF embedded font (sfnt) at offset 0x17C26 8196 bytes
font_01_sfnt_off00019b9a.bin
6dc6e07f93ae70488a19e8a398a1c6cda2f5723fc3d3cbe180c5afbb10c3611e
pdf-font-stream PDF embedded font (sfnt) at offset 0x19B9A 2864 bytes