Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd3fb501dd6dad9d…

MALICIOUS

PDF

43.1 KB Created: 2020-03-15 14:51:57 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ec352486c8f99ad979fcf680ec6b1b04 SHA-1: 4205a110272a13f9d0ddf51406e85ae2e5a6c130 SHA-256: fd3fb501dd6dad9d0c3b07087a5a6916f68da0f26fb25b1f12a7a9c599cf72f4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded external links, identified as a PDF_SEO_LINK_FARM heuristic. The document body contains a mix of seemingly random text and URLs, including the primary link http://ldb8c8.bdgct.com/uploads/1/3/0/5/130550688/130550688.html#mohabbat+aishwarya+song. This suggests the document is part of a link farm designed to manipulate search engine results or redirect users to potentially malicious content hosted on numerous domains.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ldb8c8.bdgct.com/uploads/1/3/0/5/130550688/130550688.html#mohabbat+aishwarya+song
    • http://www.klatenterprisesltd.ca/uploads/1/3/0/4/130435652/c4293e9608bc.pdf
    • http://bamestate.com/uploads/1/3/0/4/130435844/zekivevesuxutaxoru.pdf
    • http://amd11z.com/uploads/1/3/0/5/130588784/lasukirejizi.pdf
    • http://brennanforboe.com/uploads/1/3/1/1/131164066/4eb0f20950349d.pdf
    • http://yidongqipaiyouxidating.f18.ebkf.org/uploads/1/3/0/6/130621357/najexigitot.pdf
    • http://bayook.com/uploads/1/3/0/6/130605399/dasibedozoleg-datobinoviniwi-lejoz-gejujegegi.pdf
    • http://1posc.org/uploads/1/3/0/3/130323178/0e3e32167dc.pdf
    • http://rxtranparency.com/uploads/1/3/0/7/130740056/164528.pdf
    • http://www.nwbuilder.com/uploads/1/3/0/7/130775565/165776.pdf
    • http://lbsecurityservices.com/uploads/1/3/0/6/130604791/4db8fbe53.pdf
    • http://stonerosesteakhouse.com/uploads/1/3/0/7/130738797/posovadefijug_xivosumetimug.pdf
    • http://sprovencher.com/uploads/1/3/0/7/130738823/kibuwa_jekipowovage_lebutuni_fulinifib.pdf
    • http://toxique.org/uploads/1/3/0/2/130291623/eef96c5d1.pdf
    • http://wicklesspittsburgh.com/uploads/1/3/1/0/131071037/a321f83d7.pdf
    • http://cyber1risk.com/uploads/1/3/0/6/130621425/7d578abc240c3ca.pdf
    • http://1600charlestonregionalparkway.com/uploads/1/3/0/7/130776338/xapexolidobusepabiwa.pdf
    • http://www.aligrovue.com/uploads/1/3/0/3/130323186/490746.pdf
    • http://www.theacaparty.com/uploads/1/3/0/5/130588394/jegekiwuxewod_debab.pdf
    • http://mail.palme.fi/uploads/1/3/0/9/130969476/5181086.pdf
    • http://thechromaphones.com/uploads/1/3/0/9/130969335/dizaputirumuz.pdf
    • http://thebeadstack.com/uploads/1/3/0/5/130539139/7885314.pdf
    • http://shanisofficepreview.com/uploads/1/3/0/8/130874544/1232235.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000750c.bin
ab5cc05aac9ed7b8bc4fa055b0449cb15971c6a31d9555478f18e143e48fb411
pdf-font-stream PDF embedded font (sfnt) at offset 0x750C 8424 bytes
font_01_sfnt_off00009586.bin
cbd0148da7bbbff23ec47194401c3f1c03d79ba7b8135dbef378e0828e3acd51
pdf-font-stream PDF embedded font (sfnt) at offset 0x9586 1844 bytes