Malicious PDF — malware analysis report

Static analysis result for SHA-256 eea087bef42f2da7…

MALICIOUS

PDF

52.8 KB Created: 2020-06-08 05:22:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e2885b744f906b70ab4bfb5cb7dcd816 SHA-1: 4b9d5b1ee955b1ffdf53ef14bb7624bfaf87b050 SHA-256: eea087bef42f2da71d81f133a958ea3c4382f53d36ae63aff4f6efe6bd974064
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which point to PDF files with numeric slugs on various domains. The ML classifier strongly flagged this PDF as malicious. The document body, though truncated and containing garbled text, includes a URL that appears to be part of this link farm. This suggests the document is part of a link farm or SEO spam campaign, potentially leading to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gw.undesirable.us/uploads/1/3/0/9/130969888/130969888.html#th%25C3%25A9orie+de+syst%25C3%25A8me+gris+et+son+appli
    • http://opentoextraordinary.com/uploads/1/3/0/4/130488698/rerirejujezedego.pdf
    • http://solutions4insurance.com/uploads/1/3/0/8/130813876/2790657.pdf
    • http://geoffreyrafehall.ca/uploads/1/3/1/4/131453144/108297c148021d.pdf
    • http://v2.chirogust.be/uploads/1/3/0/7/130776047/3644358.pdf
    • http://goodhartcottage.com/uploads/1/3/0/6/130620567/092b5410708.pdf
    • http://claritystewardsllc.com/uploads/1/3/0/7/130740186/5762969.pdf
    • http://mail.chaku.com/uploads/1/3/0/3/130312974/6bfedcf70d9af5f.pdf
    • http://caromelocean.com/uploads/1/3/0/5/130551483/vuludog.pdf
    • http://antivirus.haubstadt.net/uploads/1/3/0/4/130476687/xumiroz.pdf
    • http://geoffreyrafehall.ca/uploads/1/3/1/4/131453144/108297c14
    • https://kipetak.files.wordpress.com/2020/06/nuvukasena.pdf
    • https://pelimude.files.wordpress.com/2020/06/xifalenixopujurekod.pdf
    • https://nudokux.files.wordpress.com/2020/06/kusorujawebevezuzopova.pdf
    • https://popuxovalu909409782.files.wordpress.com/2020/06/36231086528.pdf
    • https://zexegipofe.files.wordpress.com/2020/06/11743410745.pdf
    • https://baloxoweg.files.wordpress.com/2020/06/44512598987.pdf
    • https://purupale.files.wordpress.com/2020/06/wobanunoder.pdf
    • https://kimoripal.files.wordpress.com/2020/06/11875676083.pdf
    • https://sokorirakuzi.files.wordpress.com/2020/06/lumur.pdf
    • https://kovelika628460905.files.wordpress.com/2020/06/komemusigabifebetawoxiku.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000083bc.bin
9b789e318a0cc0dedd37261111aa869b6b450493f0d84779e5f77721cd277bea
pdf-font-stream PDF embedded font (sfnt) at offset 0x83BC 14464 bytes
font_01_sfnt_off0000b051.bin
4ef9506ee11a349461550e6b437e3786686b598308a87786035880d16624999d
pdf-font-stream PDF embedded font (sfnt) at offset 0xB051 16060 bytes