Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4d574051c002d81…

MALICIOUS

PDF

82.9 KB Created: 2020-04-11 21:30:58 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: bd2217cfb1200f479deda9352f4561c9 SHA-1: 42ae8868e6317f2521b4dd81f2dd01ce2287d7b4 SHA-256: c4d574051c002d8132248a01764778293e1325ff0ce76ab2f029354df7750de4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, a technique often used for SEO manipulation or to redirect users to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' specifically identifies this pattern. While no scripts were extracted, the presence of numerous unknown URLs suggests a potential redirection or download attempt. The document body is heavily obfuscated, preventing a clear understanding of its direct lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bluedotcbd.net/uploads/1/3/0/9/130969933/130969933.html#rolling+spell+damage+5e
    • http://iodpmsolutions.com/uploads/1/3/1/4/131408364/6124312.pdf
    • http://houeyhongcentre.com/uploads/1/3/0/2/130288924/728c3a79446.pdf
    • http://seamelive.com/uploads/1/3/0/2/130272095/fonurokeduvewuw-buzov.pdf
    • http://lovethatsteno.com/uploads/1/3/1/1/131164079/89c05.pdf
    • http://personalfinancehealth.com/uploads/1/3/0/3/130323091/3056662.pdf
    • http://roganics.net/uploads/1/3/1/4/131483632/6608af.pdf
    • http://itzinphotography.com/uploads/1/3/0/5/130589400/5625817.pdf
    • http://saunderslegal.com/uploads/1/3/1/3/131383651/sobuxakemiwevonifa.pdf
    • http://soothefix.com/uploads/1/3/0/3/130379254/xewadizemaze.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000120d0.bin
c229efd8c94ae217a7a6efe1d9336f2e6756196fbc8c6bf8e54009dc9ea7fddd
pdf-font-stream PDF embedded font (sfnt) at offset 0x120D0 8352 bytes