Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcc22efa6d4bc0f0…

MALICIOUS

PDF

38.9 KB Created: 2020-06-25 06:11:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 265ecbad9e003a3eaf7c03053f59a04f SHA-1: 01e3db3ca5497486788137c72485e73d72386ebc SHA-256: dcc22efa6d4bc0f00815e58401d4b553b82c9f5062513d7e82b4a5e0674ee86e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, many of which are dynamically generated and point to potentially malicious domains. The document body text is obfuscated but contains a URL that appears to be a lure for 'driving lessons'. The ML classifier strongly indicates maliciousness. The primary attack pattern involves SEO link farming to distribute malicious content, likely leading to further compromise via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mycloset2yours.shop/uploads/1/3/0/7/130739595/130739595.html#driving+lessons+stoke+on+trent+automatic+car
    • http://myexplorelive.com/uploads/1/3/0/5/130550729/negadogimuzivuko.pdf
    • http://tuliplawn.com/uploads/1/3/1/6/131606373/acf58c4fd50f99.pdf
    • http://alphastoneandtile.com/uploads/1/3/0/6/130604486/tuvusosex-wixotuzaluxifom-pulanatuvufasa-gozovidotovusa.pdf
    • http://serenityandglam.com/uploads/1/3/0/4/130483961/favawesoj.pdf
    • http://70-142-251-101.atemainc.com/uploads/1/3/1/4/131437873/jewokeber.pdf
    • http://justiceandadvocacy.org/uploads/1/3/0/6/130621013/7545390.pdf
    • http://cultivatedcouture.com/uploads/1/3/0/4/130435786/gifasiluz-zemilixe-gatorokajusek.pdf
    • http://dietzart.com/uploads/1/3/0/8/130815095/2081208.pdf
    • http://gaiainc.ca/uploads/1/3/0/6/130639224/nunukojigejaxel.pdf
    • http://webmail.cascadebga.org/uploads/1/3/0/4/130488851/b3ac8216.pdf
    • http://mail.fatherjim.com/uploads/1/3/0/8/130874629/50f821448a331c.pdf
    • http://74-123-75-176.mgwnet.com/uploads/1/3/0/3/130323761/7827069.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005988.bin
fc8b9d06c50e8a3a2261e97b604f4cd232fff45b533209d255582a2f730513e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x5988 5124 bytes
font_01_sfnt_off00006aeb.bin
c6547f60da449338ced17097bac75ea6ee8b84aa09a4736ce8aaa2ea3c9c9533
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AEB 10728 bytes