Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdd5cad79a5a9158…

MALICIOUS

PDF

52.1 KB Created: 2020-03-07 11:43:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 0bb94cc07889ba771a8daf00a16e44ab SHA-1: edea9bfb1b59243b3a66ed385c7e2c14fddd343c SHA-256: cdd5cad79a5a91584f0e4dc8934b25bb7c8e3442fa91f35af8fb7decab9737ea
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on different domains. The ML classifier also strongly indicated maliciousness. This suggests the document is designed to lure users to malicious or spam content, likely for SEO poisoning or phishing purposes. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific content's intent beyond link distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xianjinduboyouxi.br3h.com/uploads/1/3/0/2/130271190/130271190.html#sample+variance+of+uniform+distribution
    • http://fairenergyexchange.com/uploads/1/3/0/5/130539696/1199220.pdf
    • http://www.sbilzi.com/uploads/1/3/0/4/130476183/jejajetitinaz.pdf
    • http://themarinhandyman.maryhigginswebdesign.com/uploads/1/3/0/2/130289789/63e3a806d2e0c.pdf
    • http://mindfulsouthcarolina.com/uploads/1/3/0/6/130621458/rabuveba.pdf
    • http://hotchiwitchi.com/uploads/1/3/0/5/130544754/zapojagejab.pdf
    • http://quantumequitygroup.com/uploads/1/3/0/5/130539990/3924113.pdf
    • http://yakwelicosmeticsandmakeup.com/uploads/1/3/0/6/130620506/c19c8d8ea57.pdf
    • http://morgana.club/uploads/1/3/0/4/130483309/ruwiza-logezasufanarod-jofova.pdf
    • http://canamsoybeans.com/uploads/1/3/0/5/130544754/5635188.pdf
    • http://apexformulas.com/uploads/1/3/0/7/130776500/82ddb617a38b10e.pdf
    • http://embassybilliardinstall.com/uploads/1/3/0/3/130313590/b5cd55.pdf
    • http://backtobal.services/uploads/1/3/0/5/130588605/lugatuwo.pdf
    • http://nestednotebooks.net/uploads/1/3/0/7/130739713/8d65eb107.pdf
    • http://edcampcapital.org/uploads/1/3/0/7/130739385/ximawozaxojowog_padakadogixigal.pdf
    • http://purebarretexasstrong.com/uploads/1/3/0/2/130289613/9086236.pdf
    • http://www.insightsfocused.com/uploads/1/3/0/6/130605230/kotiwi-nokoxet-wodibav-sojiviremumux.pdf
    • http://littlethatch.net/uploads/1/3/0/5/130544781/8823569.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f95.bin
2cc75a91b954e9d35028a42183ad368b549fee394458e734d3caacbeaa98732c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F95 8536 bytes
font_01_sfnt_off0000a068.bin
cc12133150e83f368ea776114c85063f7aac9543e86b9f141e65d4cd1a9425e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xA068 3452 bytes
font_02_sfnt_off0000ac86.bin
3a6b53992a8676109c4326ccddaf93ab1c1ca747349a903fcdba2ac83462cd0e
pdf-font-stream PDF embedded font (sfnt) at offset 0xAC86 16244 bytes