Malicious PDF — malware analysis report

Static analysis result for SHA-256 f91d0d3d127ab5e2…

MALICIOUS

PDF

41.8 KB Created: 2020-03-28 08:48:17 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 1ef0410481020c849c6005df65740a41 SHA-1: 4daaa56f9485e43ec8bc564583070b4e7bb0ec03 SHA-256: f91d0d3d127ab5e2d5461138fee2c1b03f515ed6653e5ec8213f0d9d6b70a53e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or a distribution mechanism for further malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9254273-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9254273-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dessertinajar.net/uploads/1/3/0/2/130288364/130288364.html#10+ejemplos+de+polinomios+ordenados
    • http://trispotcoaching.com/uploads/1/3/0/5/130590209/kalifesemukomowur.pdf
    • http://hostmaster.lissrl.com/uploads/1/3/0/7/130739916/refawurogagi.pdf
    • http://andresbarbosa.com/uploads/1/3/0/2/130289292/7a91cb07b7b2.pdf
    • http://mta-sts.mail.firstclasspaintingandmore.com/uploads/1/3/0/6/130639143/tanodexavawer-fuzesimoxadap-kenaf-zufale.pdf
    • http://www.andrephilippephoto.net/uploads/1/3/0/6/130620893/7722384.pdf
    • http://xn--ccklb0ec8gun.com/uploads/1/3/0/2/130287890/bfbf18f4.pdf
    • http://mta-sts.mail.nizefaderz.de/uploads/1/3/0/2/130287976/vinogowapam.pdf
    • http://e-learninganddesign.com/uploads/1/3/0/2/130291416/6016784.pdf
    • http://survivingmentalhealth.com/uploads/1/3/0/6/130639504/2436154.pdf
    • http://hinduismxhistory.blog/uploads/1/3/0/2/130288542/zutekabitek.pdf
    • http://marketdigiireland.com/uploads/1/3/0/7/130738512/nobutezubesax-magemo-gufuto-jubegube.pdf
    • http://streetlevelart.com/uploads/1/3/0/2/130272424/forekuzofokoxulozege.pdf
    • http://tridesigns.net/uploads/1/3/0/6/130604524/tuxabani-mejadozu.pdf
    • http://allbacksosteo.com/uploads/1/3/0/6/130621119/9052195.pdf
    • http://www.happyheartsbookkeeping.com/uploads/1/3/0/5/130539866/gemozevufowosi.pdf
    • http://ahabancommunications.com/uploads/1/3/0/4/130476045/sereru.pdf
    • http://hillsboropestcontrol.net/uploads/1/3/0/8/130874467/98042c.pdf
    • http://hedemeisehen.com/uploads/1/3/0/9/130969708/tipopejikezurefuzeg.pdf
    • http://soinspired.net/uploads/1/3/0/4/130436182/bagafoxitumejerop.pdf
    • http://ddcarpentrymaine.com/uploads/1/3/0/7/130776421/libagiwawatabav-wugugugugob-dunisusowobo-leketopi.pdf
    • http://www.bighousesscotborders.org/uploads/1/3/0/4/130476112/7530432.pdf
    • http://mhcrimestoppers.ca/uploads/1/3/0/5/130544898/sedemofebawot_desem_vibizisuxigisad.pdf
    • http://mhcrimestoppers.ca/uploads/1/3/0/5/130544898/sedemofebawot_desem_vibizisuxigis
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000071c7.bin
03baafacd8744fe2974179735f88416fb81c1492ed0641a78a38871cb87d4bb8
pdf-font-stream PDF embedded font (sfnt) at offset 0x71C7 7580 bytes
font_01_sfnt_off00008df4.bin
e2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea
pdf-font-stream PDF embedded font (sfnt) at offset 0x8DF4 2652 bytes