Malicious PDF — malware analysis report

Static analysis result for SHA-256 e349832a1bdc6c75…

MALICIOUS

PDF

72.1 KB Created: 2020-04-08 00:53:24 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: f94332885605480ee0456f56a8cb204f SHA-1: 1c47019fda4998437200f2c479d84c9c98a5a5fc SHA-256: e349832a1bdc6c7589556a54fdddcb80f202f07f5ee8a6636fd2e7efcbb6eda3
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or redirection scheme. The document body contains garbled text and some of the extracted URLs, reinforcing the idea that the document's primary purpose is to direct users to external, potentially malicious, content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.3931

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://theinternationalcenterforreikihealing.com/uploads/1/3/1/4/131438829/131438829.html#middle+school+synonym
    • http://antium.com/uploads/1/3/0/5/130547969/namipupikuw_bopovitona.pdf
    • http://rebootforyouth.org/uploads/1/3/0/6/130639712/49643ddbcda686.pdf
    • http://www.my-bijoux.nl/uploads/1/3/0/9/130969934/95db1d523bd.pdf
    • http://chrystalscreations.ca/uploads/1/3/0/6/130620401/patamipawa.pdf
    • http://makinggoodcopsbetter.com/uploads/1/3/0/7/130739113/1878032.pdf
    • http://coffeevalleyksa.com/uploads/1/3/1/0/131070506/4928238.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off0000de49.bin
1e7f193219d252bff7b131d265a249595c1ec3ea33720dd30cb827603748dbae
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xDE49 19308 bytes
font_00_sfnt_off00006d19.bin
b1118302c5517eb61a6a239cbb0c0398f36a596cc95e76ebefef7294164c1510
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D19 7316 bytes
font_01_sfnt_off00007fff.bin
bbd465158f88620f6b89bbc14fd4053a393fda34b464cf5d9625b9580ee6f51f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FFF 10240 bytes
font_02_sfnt_off00009613.bin
db444893e1c4a0b7940346669eab76cd1d1c26d905c20ce9ccc20eba63c399e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x9613 11104 bytes
font_03_sfnt_off0000bb30.bin
03742b3af56d0894ab5df65dc3134d6d1f1537ecfbbc759efc3d5c9763d8381a
pdf-font-stream PDF embedded font (sfnt) at offset 0xBB30 6908 bytes
font_04_sfnt_off0000d1e4.bin
4c93801c4768b9cf34ec960e4f85d683fdbe353adcc5a9e70f9f8b41c5e92470
pdf-font-stream PDF embedded font (sfnt) at offset 0xD1E4 3508 bytes
font_06_sfnt_off0000fe93.bin
209285855742c6758e3ffd9d874aca3910af01dd296ec59719b0eb83c6708343
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE93 7080 bytes