Malicious PDF — malware analysis report

Static analysis result for SHA-256 d857309a9c6a4648…

MALICIOUS

PDF

53.4 KB Created: 2020-04-01 18:01:08 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: f15839698b5c796f67c4b307a63f8f92 SHA-1: 7e951db8ce61fd412deb8b000a71502879bf05e5 SHA-256: d857309a9c6a464845952b0a67325748522d6f7a1bb78b5187183fa7dd533589
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified as a link farm, pointing to various PDF files hosted on different domains. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains some of the URLs, suggesting an intent to direct users to these external resources. This pattern is often used for SEO manipulation or to distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seafoodfestivalgiveaways.com/uploads/1/3/1/4/131453464/131453464.html#cantos+catolicos+alegres+mix
    • http://nancythedatingdiva.com/uploads/1/3/0/3/130313115/noxoxeke_bizuwezena_wosesexusasa_kisilufod.pdf
    • http://nealaccountingtax.net/uploads/1/3/0/4/130488311/846658.pdf
    • http://cafeschulz.net/uploads/1/3/1/1/131163620/669610.pdf
    • http://mtlplumber.com/uploads/1/3/0/6/130604192/jomid_peguwoboxi_sojafowawovab.pdf
    • http://mainstayprivateresort.com/uploads/1/3/0/8/130873923/nidatosujaj_sunigarato_mafofasefoboru.pdf
    • http://monty2013.com/uploads/1/3/0/9/130969373/rivituginada.pdf
    • http://tokarsky1.com/uploads/1/3/1/4/131407539/281478e298b27.pdf
    • http://navycapstore.com/uploads/1/3/0/3/130323415/zajepudazosen.pdf
    • http://momsandartteachers.com/uploads/1/3/0/5/130551427/rokamewimip_wevub_mogegaj_lefenanoliw.pdf
    • http://scottsboatrepair.com/uploads/1/3/0/5/130551641/6294172.pdf
    • http://grapesnroots.com/uploads/1/3/0/5/130544687/c6f1d0fa538.pdf
    • http://ddhp.org/uploads/1/3/0/4/130483617/xefaj.pdf
    • http://ericdamianlopez.com/uploads/1/3/0/6/130603810/fopuxofi_wogozamiwimetan_jawemup.pdf
    • http://macdesignthinking.com/uploads/1/3/0/5/130538875/7661040.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000732c.bin
1957428794578a072b8983e864e5701b52391162abfb2d6d14c6295fa8a16687
pdf-font-stream PDF embedded font (sfnt) at offset 0x732C 6444 bytes
font_01_sfnt_off000082ee.bin
262ad23ccddcf75bf53de5b071a8d23c585b7f533c4bc3994edf3188b9701e71
pdf-font-stream PDF embedded font (sfnt) at offset 0x82EE 9284 bytes
font_02_sfnt_off0000a3df.bin
6ab1cd4d17ab349fbdd09211a36a2a1dc4518bd4dc087255357134f3c7815bc3
pdf-font-stream PDF embedded font (sfnt) at offset 0xA3DF 2860 bytes
font_03_sfnt_off0000adff.bin
befc078473e58f1dffe7f032225a0b33a503b61c86749ab7be3fa7fca1da02b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xADFF 17044 bytes