Malicious PDF — malware analysis report

Static analysis result for SHA-256 f8e7f23a16a4d2da…

MALICIOUS

PDF

78.1 KB Created: 2021-02-28 17:38:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 18a9b9a17805563d862e5c8c826f53ba SHA-1: a81c06a4034e65364c506120aafc8fde6c05afb2 SHA-256: f8e7f23a16a4d2da4efd1002c2643b21fcf4960da3b0fb540db0995f35d5e8df
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for external URIs, specifically pointing to a URL that appears to be a lure for 'Fedex printing email'. The PDF also contains a large number of external links, many of which are to PDF files, suggesting a link farm or SEO poisoning attempt. The ML classifier strongly flagged this PDF as malicious, indicating a high likelihood of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/123?utm_term=fedex+printing+email PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4480899/normal_5fe68bdc54063.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4483354/normal_601f03dd49a5e.pdfIn PDF document text
    • https://zazewefagawi.weebly.com/uploads/1/3/0/7/130776698/tezaror_soteb_lerivipopezir_guwetog.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412592/normal_603b213da1087.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4373998/normal_5fc6977d2a613.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4488570/normal_5fc59eda4f397.pdfIn PDF document text
    • https://zeruxitewisav.weebly.com/uploads/1/3/1/8/131856065/4f5cc0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4409254/normal_5fcbd4103323c.pdfIn PDF document text
    • https://tadilagene.weebly.com/uploads/1/3/1/3/131381422/5677914e2da7282.pdfIn PDF document text
    • https://latapelubatute.weebly.com/uploads/1/3/5/9/135960370/3998782.pdfIn PDF document text
    • https://fiwobezamarevev.weebly.com/uploads/1/3/2/7/132740324/rerilovagew-dodobetawisabof-tizomo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/dewutexorob/character_ref_letter_template.pdfIn PDF document text
    • https://s3.amazonaws.com/dupula/midnight_sun_book_synopsis.pdfIn PDF document text
    • https://s3.amazonaws.com/wolawatin/gidodoburonusezaxidixuxu.pdfIn PDF document text
    • https://s3.amazonaws.com/mogedozara/sowesufamijug.pdfIn PDF document text
    • https://s3.amazonaws.com/zuwimadaneb/install_jdk_android_studio_oracle.pdfIn PDF document text
    • https://s3.amazonaws.com/bevekizadoxuj/infinity_pool_design_guidelines.pdfIn PDF document text
    • https://s3.amazonaws.com/domegagowevag/40346709833.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8a0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE8A0 4800 bytes
SHA-256: 73e917535a4b79afb6d31a8a065ba748af1b5897f3b91d7c05d2cd20adfafd1c
font_01_sfnt_off0000f8d6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF8D6 10532 bytes
SHA-256: 6df142a829e424060148112e79e94bf61fa0281903d860624338468943a26f6d
font_02_sfnt_off00011ceb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11CEB 4324 bytes
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176