Malicious PDF — malware analysis report

Static analysis result for SHA-256 741d407a04928445…

MALICIOUS

PDF

36.4 KB Created: 2020-04-05 16:28:18 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: b561717cfcffd5f30cd5c90d2127fe24 SHA-1: 5bba576f5c8975b38a1846280e92a761c0033772 SHA-256: 741d407a049284454a94b52c688a6c3a87246eb2f5b0e28f39f5709530ba6a2e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF document contains a heuristic firing for a link farm, indicating it hosts a large number of external links to other PDF files across various domains. The ML classifier also strongly flagged this PDF as malicious. The embedded URLs suggest a tactic to redirect users to potentially malicious content or for SEO manipulation purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://volcanis.net/uploads/1/3/0/7/130738796/130738796.html#market+sizing+consulting+case
    • http://tillerridge.com/uploads/1/3/0/5/130550825/tejaroxupunave.pdf
    • http://theoriginalyoungmen.org/uploads/1/3/0/7/130776183/belisigavujebazekom.pdf
    • http://ammjenoreste.com/uploads/1/3/0/7/130739000/9409305.pdf
    • http://khdggaw.com/uploads/1/3/0/7/130739431/pofab.pdf
    • http://rusticrat.com/uploads/1/3/0/6/130621484/popodenuxin_dapivisefij.pdf
    • http://newmexicoseo.net/uploads/1/3/0/4/130483684/9a02f3.pdf
    • http://envasesbiobiospa.com/uploads/1/3/0/5/130543771/jolaxexiveri.pdf
    • http://facedesignsweden.com/uploads/1/3/0/6/130620649/8251072.pdf
    • http://lavieenrosemacarons.com/uploads/1/3/1/3/131382274/3027806.pdf
    • http://bearridgedoodles.com/uploads/1/3/1/4/131406835/9d3af.pdf
    • http://landsitesavailable.com/uploads/1/3/0/6/130604114/jujob.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006774.bin
d183742f14591fbf0f40f3f46d927d8d432198a2155eac647609ca5a0875ffb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6774 7616 bytes