Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b4a13bd037cd8df…

MALICIOUS

PDF

130.2 KB Created: 2020-03-21 19:46:32 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ce3987d4468edb032a8b36aef7f99904 SHA-1: f8ec182dec88da9cb9655f50c509d850e6024045 SHA-256: 7b4a13bd037cd8dfdfee6f27f1533acdb67ddefa1bb4487db8e9d0fbb0ee4132
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or distribution network. The ML classifier also strongly flagged this PDF as malicious. The primary attack pattern appears to be directing users to a large collection of external PDF files, potentially for SEO manipulation or to host malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://flyingmonkeygarage.com/uploads/1/3/0/2/130271205/130271205.html#historia+del+futbol+pdf+resumen
    • http://recipetracks.com/uploads/1/3/0/3/130313398/1494507.pdf
    • http://blusunbeauty.com/uploads/1/3/0/4/130477633/xufaliwapomi.pdf
    • http://dinosgrilledburger.com/uploads/1/3/0/4/130476732/86fda65c6f91.pdf
    • http://justrightdm.gruupmeet.com/uploads/1/3/0/6/130605206/c856b97184bf92.pdf
    • http://burchettequine.com/uploads/1/3/0/8/130814250/6741382.pdf
    • http://wmaxconsulting.com/uploads/1/3/0/6/130639652/retovawig.pdf
    • http://www.oroshaziingatlan.com/uploads/1/3/0/5/130544240/derawofo.pdf
    • http://xtremexxlbullyz.com/uploads/1/3/0/8/130813663/zelenojiwum.pdf
    • http://medistay.org/uploads/1/3/0/6/130621909/ea26045a9833.pdf
    • http://paycationpeprally.com/uploads/1/3/1/0/131070115/fc648.pdf
    • http://rosecityinspections.com/uploads/1/3/0/7/130776393/610d4a5815b.pdf
    • http://mx.mx.cheyenne.space/uploads/1/3/0/6/130604445/miwoxelikak-wiruridelola-mitujoladaxe.pdf
    • http://www.turbo23.es/uploads/1/3/0/2/130289597/2361272.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b22c.bin
9fef0759358c9682dd1fafd536f6d9af5884c09197f14c1ca1e7c78318208460
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B22C 11932 bytes
font_01_sfnt_off0001da1d.bin
0ef1112e50e2a86488aadde4d8a477a3649c66578d8f2a84f2c6ad20bbddbbf8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DA1D 2732 bytes
font_02_sfnt_off0001e3ca.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E3CA 16036 bytes