Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fc2640b141b766c…

MALICIOUS

PDF

35.0 KB Created: 2020-03-13 03:02:10 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 0094ce0ee662edee7b2ad7ce13ae49fc SHA-1: 1e3ba464dc85a39b937f79953fb01700bbc01360 SHA-256: 7fc2640b141b766c279cead7ef6139b7bb1cef0cde564914204fdb44107cbeb1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous links to external websites, a common tactic for distributing malware or phishing content. The document body explicitly mentions 'Gta san andreas ultimate cheats mod download' and includes a URL pointing to an HTML file, suggesting a lure to download potentially malicious content. The ML classifier strongly flagged this PDF as malicious, reinforcing the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://adsl-63-204-18-39.benefitplans.org/uploads/1/3/0/9/130969032/130969032.html#gta+san+andreas+ultimate+cheats+mod+download
    • http://mail.udrugamoldavit.com/uploads/1/3/0/4/130483230/9149245.pdf
    • http://outronaut.com/uploads/1/3/0/3/130324063/bfd1ccce.pdf
    • http://imslimitedllc.com/uploads/1/3/0/4/130483351/dudux.pdf
    • http://rsdconsultingllc.org/uploads/1/3/0/5/130588461/nidode-fugez.pdf
    • http://raj108yoga.com/uploads/1/3/0/6/130620537/resugazuwekezokew.pdf
    • http://mattansini.com/uploads/1/3/0/7/130775108/wekimofes.pdf
    • http://lattematte.com/uploads/1/3/0/5/130550738/dixafipirefatu.pdf
    • http://christswayministries.org/uploads/1/3/0/7/130776082/2886331.pdf
    • http://www.zacarah.com/uploads/1/3/0/5/130588796/ruxeve-wafinuwukiz.pdf
    • http://mizuno-environmentaldesign.com/uploads/1/3/0/2/130272092/dasad.pdf
    • http://mimariposadesigns.com/uploads/1/3/0/4/130489019/sajafowemusexol-vagedomunof.pdf
    • http://www.prosemis.net/uploads/1/3/0/2/130288378/susasiwemoxud-jijaturudu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005d06.bin
3acca1b12f46a9e4c5e889d9f2e7ae7e1466ed1cc7665349d20bc632dc952d02
pdf-font-stream PDF embedded font (sfnt) at offset 0x5D06 9628 bytes