Malicious PDF — malware analysis report

Static analysis result for SHA-256 e51f31a6827e461b…

MALICIOUS

PDF

60.6 KB Created: 2020-03-28 05:27:55 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 090fe178f6e5efdcbba79152539aa13e SHA-1: 796a10f843a15c2ed59c753bd352b11da4e1a5cf SHA-256: e51f31a6827e461bb54cd79516110a82a5f43a1cf1327ae0adfaf969c77cda6b
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, a technique commonly used for SEO poisoning or to direct users to malicious sites. The ML classifier strongly flagged this PDF as malicious. The document body contains text that appears to be a lure, referencing a download, and includes the primary malicious URL. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://societaenergeticasarda.com/uploads/1/3/0/7/130775337/130775337.html#el+gran+silencio+vi-vo+descargar
    • http://my150reconcilliation.ca/uploads/1/3/0/7/130740489/2c8a7b8b3ca8.pdf
    • http://bbnla.com/uploads/1/3/0/2/130288761/7641fc37735d.pdf
    • http://healthsolutionsllc.com/uploads/1/3/0/6/130604798/vurizipokusederikoxe.pdf
    • http://ecoqueencleaning.com/uploads/1/3/0/8/130814575/6d4434.pdf
    • http://inkwellretreats.com/uploads/1/3/0/6/130604744/fanefadimegobezat.pdf
    • http://www.sandyhookhoax.com/uploads/1/3/0/8/130874413/8a87a.pdf
    • http://odinzen.com/uploads/1/3/0/7/130739132/potipozugojele.pdf
    • http://weeknightworkout.com/uploads/1/3/0/6/130605017/sepazewirokurasatal.pdf
    • http://votebyronmartin.com/uploads/1/3/0/3/130323968/7648196.pdf
    • http://impiantimatec.com/uploads/1/3/0/3/130313316/sawefijenirane.pdf
    • http://newmarketcrossfit.com/uploads/1/3/0/6/130620729/2493774.pdf
    • http://lucernecountryclubrvpark.com/uploads/1/3/0/3/130323566/piwizafevasalom-kivasiwofufisu.pdf
    • http://southlandbaptisttemple.net/uploads/1/3/0/3/130379248/6868236.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007216.bin
8f3c6ac098290535930a62471c59cc01db724254982e8b22b5293056f919eaaa
pdf-font-stream PDF embedded font (sfnt) at offset 0x7216 20800 bytes
font_01_sfnt_off00009189.bin
3212cfd140bfd10addaffdde23fe17c6b0a0f3a7f2797f7ac4ed550b71556e2d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9189 11264 bytes
font_02_sfnt_off0000b704.bin
bf9b9d10e9d9890ab9d1a7ec18efb3f3b6daf3583292778e90f0943f39e87841
pdf-font-stream PDF embedded font (sfnt) at offset 0xB704 2600 bytes
font_03_sfnt_off0000c027.bin
95787e76bb71f6f7dedc306ddfaab1c356382df80c6dfb1591125dc6190eb6ce
pdf-font-stream PDF embedded font (sfnt) at offset 0xC027 3048 bytes
font_04_sfnt_off0000cc9d.bin
b62d607af92872c00ae0a7ce6ea83f32622fcab5c367e2c25821bed2d561eded
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC9D 16188 bytes