Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfb8ef45c7404850…

MALICIOUS

PDF

47.0 KB Created: 2020-06-09 08:42:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1f2250d29a27fef6bb50d51b54ec18ee SHA-1: 21b954fea4bfc75f944f24ee500cd5f60fe9db18 SHA-256: cfb8ef45c74048503abc2c6ef0800e661fd788a23d4949f727ec6dcada7d1bd0
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, a technique often used for SEO poisoning or to redirect users to malicious websites. The ML classifier strongly flagged this PDF as malicious. The document body contains obfuscated text and URLs, including a nested URL pointing to 'ronavian.com' and another to 'raschcyberlaw.com', suggesting a lure to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tcsonline.net/uploads/1/3/0/5/130589100/130589100.html#http%253A%252F%252Fronavian.com%252Fuploads%252F1%252F2%252F9%252F0%252F129090826%252F129090826.html%253Fpixel+full+movie+online+free
    • http://raschcyberlaw.com/uploads/1/3/1/8/131856492/209a13209d8fb8.pdf
    • http://clearwaterconcerts.org/uploads/1/3/0/8/130813592/pawiwa.pdf
    • http://donate-car.eu/uploads/1/3/0/8/130873983/genoke-bitulet-jojodibi-novibamufe.pdf
    • http://easystudentconnect.com/uploads/1/3/0/2/130287295/zefebamevita.pdf
    • http://brantleytrainingsystems.com/uploads/1/3/0/3/130379482/vukas_vamape_wafekegodapu.pdf
    • http://scrmedical.com/uploads/1/3/1/4/131454580/pejadadamiwelo-godowamogofovo-puduposi-vevekekazuju.pdf
    • https://fafigunik.files.wordpress.com/2020/06/74957998226.pdf
    • https://kidugusex.files.wordpress.com/2020/06/durajefid.pdf
    • https://pipoxoxid.files.wordpress.com/2020/06/88734421199.pdf
    • https://migufelasot.files.wordpress.com/2020/06/17965669243.pdf
    • https://pomurulive.files.wordpress.com/2020/06/virotado.pdf
    • https://zajifikaviku.files.wordpress.com/2020/06/70410962046.pdf
    • https://nogilofonula.files.wordpress.com/2020/06/21469633113.pdf
    • https://fokewofupipi.files.wordpress.com/2020/06/wekava.pdf
    • https://mapikupe.files.wordpress.com/2020/06/nedazisolam.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000608e.bin
047f3f4cadc8d1bfed275dc2ab80f8ee78d633af44b26323e16289ba649f80be
pdf-font-stream PDF embedded font (sfnt) at offset 0x608E 3720 bytes
font_01_sfnt_off00006dba.bin
3c2a1c9ad9795b2210bf2daeec5345ac28cdd4ff9a5a3e1da496d03f9b428223
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DBA 11912 bytes
font_02_sfnt_off00009641.bin
fd8bcd6c9d5653f5ca42e7a0da8c37bb11293382d085f187bfc5f0104eb230c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9641 16832 bytes