Malicious PDF — malware analysis report

Static analysis result for SHA-256 432a697f076f3e47…

MALICIOUS

PDF

57.8 KB Created: 2020-03-27 11:52:49 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 09e645580cb131573cd2090b8ae49c31 SHA-1: 50b925fc4d6fd76330b37e084890a5d1d400bd26 SHA-256: 432a697f076f3e477e6e2f51a40846cf8eaa87c60830002b7234f54842227b16
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous external links, many of which point to PDF files on unrelated domains. The document body explicitly mentions 'Abbyy finereader 12 full crack 64bit', indicating a lure for pirated software. The heuristic 'PDF_SEO_LINK_FARM' further suggests a malicious intent to create a link farm, likely for SEO manipulation or to distribute malware disguised as software cracks. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://onlytopsaler.site/uploads/1/3/0/5/130589133/130589133.html#abbyy+finereader+12+full+crack+64bit
    • http://www.livingedgehome.com/uploads/1/3/0/8/130874001/6837015.pdf
    • http://minchatholdings.com/uploads/1/3/0/5/130542908/radisaxemudiduxotir.pdf
    • http://carpetcleaningkamloops.com/uploads/1/3/0/7/130739318/3aa0a0a7c6809e.pdf
    • http://taralavery.com/uploads/1/3/0/6/130620282/rupisenokutetosifi.pdf
    • http://aircontrolexperts.com/uploads/1/3/0/5/130541765/3776584.pdf
    • http://www.mundfordconnect.com/uploads/1/3/1/0/131069777/ca514fe2bc69c.pdf
    • http://prismaquinceevents.com/uploads/1/3/0/7/130776413/bozawo.pdf
    • http://northamptondowntown.com/uploads/1/3/0/5/130538875/896543.pdf
    • http://360casecamp.com/uploads/1/3/0/2/130271076/9893465.pdf
    • http://aialumassage.com/uploads/1/3/0/5/130588856/2232524.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000930b.bin
1bb058f8827ad90afc526fb8fb0eda5c267dd3ab37b1add6c97130c09c9e2978
pdf-font-stream PDF embedded font (sfnt) at offset 0x930B 12316 bytes
font_01_sfnt_off0000b9d1.bin
6fdb4bc8cba1ce94eb51663453091bbad40684b46b13f39817d25153345ed8a7
pdf-font-stream PDF embedded font (sfnt) at offset 0xB9D1 24052 bytes