Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd67c546560b35c0…

MALICIOUS

PDF

41.4 KB Created: 2020-06-06 01:26:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cfdfaaf2223dc0ccd5e8de6a2f2bae47 SHA-1: 8216a19710f4ba596dd652dfe451196a6e0a3521 SHA-256: dd67c546560b35c077efaefa7ee696389479a49e50f1e4184f95f10692e855c8
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of external links, identified as a link farm, suggesting a deceptive purpose such as SEO manipulation or hosting malicious content. The ML classifier strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, but the sheer volume of external URLs points to a high likelihood of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://emintgroup.net/uploads/1/3/0/7/130775220/130775220.html#eve+university+npc+damage+types
    • http://35dollar-tickets.com/uploads/1/3/1/3/131397987/3fa3ef.pdf
    • http://bookshrinkediting.com/uploads/1/3/0/6/130620625/terujid-zosasujutataku-girale.pdf
    • http://thissideoftherainbow-org.txlpcsupervision.com/uploads/1/3/0/7/130775393/bogesut_dotube.pdf
    • http://mrzelectric.com/uploads/1/3/0/6/130605263/nadadexuv.pdf
    • http://constructioninsurance.net/uploads/1/3/0/7/130739153/9646245.pdf
    • http://sftutoring.org/uploads/1/3/1/8/131857071/9188191.pdf
    • http://thelearningagencylab.com/uploads/1/3/0/2/130291579/bakebinu-juxomamib-lukivedeg-bidizav.pdf
    • http://lsbarbecue.com/uploads/1/3/0/5/130542935/komivo-gejitedusarisu-sakefanuv.pdf
    • http://gvrclubs.casapaloma2.org/uploads/1/3/0/9/130969191/7ecd9e82870c.pdf
    • http://emintgroup.net/uploads/1/3/0/7/130775220/terms.html
    • http://emintgroup.net/uploads/1/3/0/7/130775220/dmca.html
    • http://emintgroup.net/uploads/1/3/0/7/130775220/policy.html
    • https://vokovibawewu126902322.files.wordpress.com/2020/06/89536832977.pdf
    • https://tumimusazos.files.wordpress.com/2020/06/16551182883.pdf
    • https://kisinawaku.files.wordpress.com/2020/06/77012023788.pdf
    • https://rusevaleno.files.wordpress.com/2020/06/79279169608.pdf
    • https://wivobajet.files.wordpress.com/2020/06/93039540311.pdf
    • https://kavafof.files.wordpress.com/2020/06/valajudalajaxiper.pdf
    • https://merefipo.files.wordpress.com/2020/06/19729311819.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007612.bin
ce6cc87ff8272843cea4f1424d6115da39ff78fbbf9db05b116f6305aef8cc9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7612 10348 bytes