Malicious PDF — malware analysis report

Static analysis result for SHA-256 4741447a30ab789e…

MALICIOUS

PDF

46.8 KB Created: 2020-04-01 14:26:51 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: f7063a601a10ad9d8b594c6fa85ca98b SHA-1: 09c016b13b3253e245d54c5dd42dcabb2452bf22 SHA-256: 4741447a30ab789e39092a0f68b63c103677a24953eed4463cfbb4386013a798
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection tactic. The ML_NYX_PDF_MALICIOUS classifier strongly supports the malicious nature of this document. No scripts were extracted from this sample, and the document body is heavily obfuscated, but the sheer volume of external links points to a malicious intent, likely for SEO manipulation or to distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://clinipal.net/uploads/1/3/1/3/131380589/131380589.html#kuana+torres+kahele+napua+greig+james+ford+murphy
    • http://forthoseabouttorockacademy.com/uploads/1/3/0/5/130547771/gigeliresi.pdf
    • http://shobingg.net/uploads/1/3/0/3/130323422/tubizavo-seruvu.pdf
    • http://taylortransit.net/uploads/1/3/0/2/130272442/8094482.pdf
    • http://theroyalpineapple.com/uploads/1/3/1/4/131483110/jofekugidonuvad-sigugediwufekab-zidakedod-bilukovolajij.pdf
    • http://advantageonellc.com/uploads/1/3/0/5/130588984/dfa3a1b1627.pdf
    • http://godsearthlyangels.com/uploads/1/3/0/7/130740087/pixesafugufik-baxagawinokilo.pdf
    • http://peoplepathwaysplace.com/uploads/1/3/0/6/130639026/rijagako.pdf
    • http://reconmetals.ca/uploads/1/3/0/6/130640227/kalegix.pdf
    • http://solutionbooklet.com/uploads/1/3/0/4/130483479/83a9a4242eb7.pdf
    • http://mythmakerclothingco.com/uploads/1/3/0/7/130740097/jawijevovedarevil.pdf
    • http://tbpoetry.com/uploads/1/3/0/7/130739536/c148c13868c.pdf
    • http://nowwhatdoula.com/uploads/1/3/0/5/130545885/kipurokokaleduz.pdf
    • http://the-big-one.org/uploads/1/3/0/8/130813827/1913241.pdf
    • http://inspiremetherapy.com/uploads/1/3/0/2/130272284/senagilanirekobegena.pdf
    • http://openrangeriders.com/uploads/1/3/0/2/130272474/2549306.pdf
    • http://nathaliezender.com/uploads/1/3/1/3/131398254/339f42d8e1.pdf
    • http://poochiezprojectz.com/uploads/1/3/0/2/130273791/b6868.pdf
    • http://perhamfoodshelf.com/uploads/1/3/0/6/130621335/volawemuz.pdf
    • http://picolombia.com/uploads/1/3/0/8/130813144/1532610.pdf
    • http://ecologiesofprosperity.com/uploads/1/3/1/4/131406395/kekinilomowosul.pdf
    • http://biobornayurveda.com/uploads/1/3/0/5/130539297/12b7a670.pdf
    • http://white-cake.com/uploads/1/3/0/5/130547689/lilazew.pdf
    • http://mansionsiemreap.com/uploads/1/3/0/5/130539871/nofojufomivaxi-betitujiban.pdf
    • http://chrisparkersportfolio.com/uploads/1/3/0/2/130288986/jagafutopufokobide.pdf
    • http://mrbeavercreek.com/uploads/1/3/0/6/130605089/8911443.pdf
    • http://chrisparkersportfolio.com/u
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000078a8.bin
bc902c3f11148c1215fd8189da1f6b8912f334cf0d3efc07398ccddee2aa4fbb
pdf-font-stream PDF embedded font (sfnt) at offset 0x78A8 8300 bytes
font_01_sfnt_off000097d9.bin
7452b6b49b2d67df973eecb7580c7a2fe344bf55d7b957b3ade50b6969c50269
pdf-font-stream PDF embedded font (sfnt) at offset 0x97D9 16068 bytes