Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd01a93d2a3adf3d…

MALICIOUS

PDF

57.0 KB Created: 2020-12-08 17:52:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 8f2477d854854d38309452f2400275c9 SHA-1: 62714105ef44eaefa0a5670a3d11fa746123d06e SHA-256: fd01a93d2a3adf3d302bfa94dcdbe8f3eb598b7c6f2b2bc3ae8bac3439e18c18
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The document body, though heavily obfuscated, contains text related to "Gainesville sun obits" and the authoring application "wkhtmltopdf", suggesting a potential SEO spam or link farm tactic. The presence of embedded URLs and the ML classifier's high confidence score indicate malicious intent, likely to redirect users to malicious sites or distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/strik?utm_term=gainesville+sun+obits PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4450048/normal_5fc14282b4f3d.pdfIn PDF document text
    • https://zolezuborejizo.weebly.com/uploads/1/3/4/4/134444688/1788fc.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4456996/normal_5fb30aeb0309a.pdfIn PDF document text
    • https://tazomisoz.weebly.com/uploads/1/3/4/3/134344853/walavo_xuxagixodakot_dubupa.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393776/normal_5f961212a9930.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421224/normal_5f9c9f3ca0a82.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/53689293-3695-40af-9229-b607df1f72e5/rohs_smart_bracelet_manual.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0e2fd6b97992eb55c026f/t/5fcf231b57846c5b834fe2eb/1607410460191/best_road_racing_cars_forza_horizon_4.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc663662e537a05ef2e8a84/t/5fca6c6127154a49e92a5d73/1607101540595/8615808295.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0eacbc14dfd36fef1915a/t/5fc242ea5147b148047d3667/1606566635279/laxosajimekapogawov.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a6db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA6DB 4812 bytes
SHA-256: 0370be05a1e7a672bda4ec620e284cfc757ece6309c90c9be3b45cd071ceb557
font_01_sfnt_off0000b751.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB751 9760 bytes
SHA-256: 0f90a374272f324d5439eef7b63b87a36aa556e5886293fb52aa78771bea9397