Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f01687a480ce3f8…

MALICIOUS

PDF

39.4 KB Created: 2020-06-16 13:45:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 984e461e66f383aaa90f9828c65c3f32 SHA-1: c6eb7a8f00dd90b8d07a90465c71e9ebe88c8051 SHA-256: 3f01687a480ce3f86b7e5f0006eb214f45e1a536ad265287ba5a30c3c958aeec
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to other PDF files hosted on various domains. This behavior is indicative of a link farm designed to attract search engine traffic and potentially lure users into downloading malicious content. The document body text, while partially corrupted, includes phrases like 'pdf free download software for windows xp', reinforcing the lure. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://prayassociates.gift/uploads/1/3/1/8/131871721/131871721.html#pdf+free+download+software+for+windows+xp
    • http://weeblyreview.com/uploads/1/3/1/6/131636969/xigaj.pdf
    • http://101ic.com/uploads/1/3/0/5/130551186/kodoritetafebojulu.pdf
    • http://perfectlightfilmfestival.com/uploads/1/3/0/3/130379118/61f9f65c.pdf
    • http://mta-sts.davidmichaeldesign.com/uploads/1/3/1/3/131379874/7112120.pdf
    • http://thisoklahome.com/uploads/1/3/0/4/130491599/495807.pdf
    • http://boxfivepodcast.com/uploads/1/3/0/4/130435738/bd87c18d.pdf
    • http://besthandymanbrooklyn.com/uploads/1/3/0/9/130969199/6479332.pdf
    • http://teaching-philosophy-be-amazing.com/uploads/1/3/0/2/130289226/talatusovavime_mavegit_jilija_rixokubanubev.pdf
    • http://hostmaster.digitalmultimeter.ch/uploads/1/3/0/9/130969158/kibezikawizafusixu.pdf
    • http://mta-sts.mail.nicamap.com/uploads/1/3/0/7/130776370/woxetojogupoga.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005809.bin
bff899e10f9263a51e3b0b83fa02c4585571c89a11228895e04db86a19f260d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x5809 10088 bytes
font_01_sfnt_off00007ae0.bin
c988415812f594187b0a0ed75dc52802e798e1695b49bd300f8412a65040a449
pdf-font-stream PDF embedded font (sfnt) at offset 0x7AE0 16204 bytes