Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7fd0f2f41ec674e…

MALICIOUS

PDF

40.7 KB Created: 2020-04-27 19:04:25 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d67f5f64c6af8d2a9361186a5a892a59 SHA-1: 7a0d9634610d297d99115f18fd7cb1c1e549deeb SHA-256: e7fd0f2f41ec674e0f45301dbdcaec4468c9a7f1e612e39b8e9a3e5d170a7470
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, many of which are dynamically generated and point to suspicious domains, indicating a link farm or SEO poisoning tactic. The ML classifier strongly flagged this PDF as malicious. The document body, though obfuscated, contains a reference to 'My talking tom 2 video' and an external URL, suggesting a lure to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://okpins.net/uploads/1/3/0/4/130488105/130488105.html#my+talking+tom+2+video
    • http://thistletransmission.com/uploads/1/3/1/4/131453780/6f7a4d78377.pdf
    • http://canyoncollective.co/uploads/1/3/0/5/130539718/755280.pdf
    • http://surfrescue.club/uploads/1/3/0/5/130539034/4081503.pdf
    • http://bitchinbettie.com/uploads/1/3/0/2/130274368/puxofatajitineg_kuzopumutag.pdf
    • http://updanceacademy.com/uploads/1/3/1/4/131454190/a48a12bb2b1e7.pdf
    • http://foundationclosing.com/uploads/1/3/0/2/130271229/778447.pdf
    • http://giovannalungu.com/uploads/1/3/0/6/130605502/zapizupa.pdf
    • http://koolguysair.com/uploads/1/3/0/6/130604286/9727175.pdf
    • http://koppsinmalawi.com/uploads/1/3/1/4/131454316/jafominuji-tavuxetigagiv.pdf
    • http://iamquintessentialnails.com/uploads/1/3/0/9/130969243/pepiru.pdf
    • http://donknation.com/uploads/1/3/1/4/131454151/wonima.pdf
    • http://independantpattesting.com/uploads/1/3/0/6/130622084/rujidapidarasa.pdf
    • http://koppsinmalawi.com/uploads/1/3/1/4/131454316/jaf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006935.bin
132bf27c1972cefba6c633f871e1a3b194d749aa011c2bd227a907c162ff08b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x6935 9028 bytes
font_01_sfnt_off00008b9e.bin
be7acebb918112476a9f8536c0cb22409c8d798b2d409f02b21d7c591f3c0a10
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B9E 2496 bytes