Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc2b741903376089…

MALICIOUS

PDF

72.6 KB Created: 2020-04-12 03:47:01 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d7bd1cff51fa5cb7dab6592edfb50604 SHA-1: 1d95c42ca995350534b49aea294d02ecc3e4defe SHA-256: dc2b7419033760892737fdc338953aacb4ef2c0c7368256db4dcc94ed4eb7494
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to various domains, characteristic of a link farm designed for SEO manipulation. The primary heuristic indicates a mass external PDF link farm, suggesting the document's purpose is to redirect users to potentially malicious or spam content hosted on these numerous domains. No scripts were extracted, and the document body is heavily obfuscated, limiting further analysis of the immediate payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://littleedenranch.com/uploads/1/3/0/7/130739598/130739598.html#numero+de+protones+y+neutrones+de+bromo
    • http://ransolisprofessionalportfolio.com/uploads/1/3/0/6/130621272/0c917.pdf
    • http://2daycashoffer.com/uploads/1/3/0/2/130287873/8b41eb9865a7.pdf
    • http://breakingpointllc.com/uploads/1/3/1/3/131381443/pomogofovu-tezux-pizaxixew.pdf
    • http://adamhenryink.com/uploads/1/3/0/5/130588216/tesofazese.pdf
    • http://denalitravel.org/uploads/1/3/0/5/130590532/panuw-pokiturem.pdf
    • http://garycedeira.com/uploads/1/3/0/5/130543305/salegoko.pdf
    • http://jordanie-vakanties.nl/uploads/1/3/0/2/130274305/86c6dd.pdf
    • http://ebbtide.blog/uploads/1/3/0/6/130622091/dcef7a38ae19a7.pdf
    • http://securethecrownza.com/uploads/1/3/0/5/130588291/1849706.pdf
    • http://sorrentobobcatandlandscaping.com/uploads/1/3/0/6/130639643/mepononujoki.pdf
    • http://erikarobinsonreadings.com/uploads/1/3/0/4/130435622/tepor.pdf
    • http://elli3d.com/uploads/1/3/0/4/130476506/bevawotikikete.pdf
    • http://cerecdl.com/uploads/1/3/0/7/130738679/5281203.pdf
    • http://breakingpointllc.com/uploads/1/3/1/3/131381443/pomogofovu-tezux-pi
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f2f.bin
3e7a34245ebe8c45612dfcc60ada2a41f299995e59537c80ff7fa73eac083363
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F2F 12536 bytes
font_01_sfnt_off00008bfc.bin
1ab58d80a52d3e77323810cc23ae6bc7bdb6ee14b0e176862c2a2718022d8ff6
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BFC 12084 bytes
font_02_sfnt_off0000b2c8.bin
5f280b5468dcc15281be23e555814e9dc83d6d884cab1e9bfff971a7419bdfb2
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2C8 12376 bytes
font_03_sfnt_off0000da8c.bin
b9bc154b00b9a8de084f4c4b077021466b18978b58793a20d7b176c84d02a1e3
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA8C 19212 bytes
font_04_sfnt_off0000f909.bin
327b7cedd022c54ad43487f6bf32c9416cc3a8e527faf830061f1b666d5712a7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF909 9272 bytes