Malicious PDF — malware analysis report

Static analysis result for SHA-256 37590d4030549365…

MALICIOUS

PDF

35.5 KB Created: 2020-04-18 08:23:27 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 1cb5b07906647c324d6626c30f772be8 SHA-1: cb74c1633e70d6638b1d57b4aa01aff41c742733 SHA-256: 37590d4030549365b7fcfd799f6cbd45293cbc26186249c2540230676bf4b44d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

This PDF document was flagged as malicious by an ML classifier. It contains a large number of embedded external links to other PDF files hosted across numerous domains, a technique often used for SEO spam or to distribute further malicious content. The document body contains garbled text but includes a reference to 'Icmje and gpp guidelines' and the authoring application 'wkhtmltopdf', suggesting a potential lure related to academic or professional guidelines, with the links serving as the primary malicious mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://karmacleaning206.com/uploads/1/3/0/2/130272333/130272333.html#icmje+and+gpp+guidelines
    • http://idyllicsolutions.com/uploads/1/3/0/6/130605341/5674554.pdf
    • http://kennebecpropertymaintenance.com/uploads/1/3/1/4/131437984/f51c3b829d4b.pdf
    • http://belkablossoms.com/uploads/1/3/0/7/130739454/2241308.pdf
    • http://proballerreport.com/uploads/1/3/1/4/131438241/bokexuvi_sogenirisibelim_lepugumumuzeguf_robigepuwonajat.pdf
    • http://gathermv.com/uploads/1/3/1/3/131398177/3227435.pdf
    • http://3musesworkshops.com/uploads/1/3/0/7/130740338/pekamoteb.pdf
    • http://uncommondwellings.com/uploads/1/3/0/3/130313063/rebapajuzamu_raramugoxe.pdf
    • http://personaltrainingzurich.com/uploads/1/3/0/4/130483052/7064553.pdf
    • http://ardentartistmanagement.com/uploads/1/3/1/6/131637034/b985419328a79.pdf
    • http://musiccitydoubledutch.org/uploads/1/3/1/4/131452782/8118434.pdf
    • http://kmaysphotography.com/uploads/1/3/0/5/130541623/2814143.pdf
    • http://aussiewrestling.com/uploads/1/3/0/3/130379424/945af.pdf
    • http://laurasimao.com/uploads/1/3/0/5/130588207/movizudofuwinakopuka.pdf
    • http://exbhome.com/uploads/1/3/0/8/130874042/6101708.pdf
    • http://cursosnutricion.org/uploads/1/3/1/4/131406284/768107.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006600.bin
88e944a1514bd6f50bce9687199a380d2875869919c046802a97fb19407ffa89
pdf-font-stream PDF embedded font (sfnt) at offset 0x6600 7088 bytes