Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca1516056f821781…

MALICIOUS

PDF

40.1 KB Created: 2020-03-08 00:43:50 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 08726974c2ecc61b53e7d1983bb7e094 SHA-1: 89e968822d90c74a76dd05bb09ddc0b83120e64d SHA-256: ca1516056f821781a534143743bf5ebc2c813aba0545924a0f15bd86b88d0c02
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged by an ML classifier as malicious. It contains a large number of external links, many of which point to PDFs with numeric slugs, suggesting a link farm or SEO abuse tactic. One of the embedded URIs points to an HTML file, which could potentially host further malicious content or phishing lures. The document body itself is largely unreadable, but the presence of the 'kallax shelving unit ikea' string and the wkhtmltopdf authoring application suggests it might be a lure document generated by a tool.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ruthcampbell-paintings.com/uploads/1/3/0/5/130551904/130551904.html#kallax+shelving+unit+ikea
    • http://www.rubenthebarber.com/uploads/1/3/0/5/130589131/08715153834e677.pdf
    • http://wcmcphailhomeinspections.com/uploads/1/3/0/5/130589315/bodosarabobupaf_linematexe.pdf
    • http://newbethellg.com/uploads/1/3/0/6/130604465/vedomuxirozaxi.pdf
    • http://tabithatikkle.com/uploads/1/3/0/4/130435888/fagutolezenafi.pdf
    • http://www.rooftopviewpwc.com/uploads/1/3/0/3/130324050/e3246158cc23.pdf
    • http://nadidah.net/uploads/1/3/0/7/130775584/levavenujip-fofebimolojobo.pdf
    • http://nesteam.co.il/uploads/1/3/0/5/130539093/fizujileg-kiwitisujoxugux.pdf
    • http://postacuteepisodes.com/uploads/1/3/0/6/130604145/2abcc.pdf
    • http://archimmo.ca/uploads/1/3/0/2/130270882/9035746.pdf
    • http://savesexpress.com/uploads/1/3/0/6/130639513/615790.pdf
    • http://honourcoffee.com/uploads/1/3/0/8/130814311/17d396.pdf
    • http://h4sd.com/uploads/1/3/0/2/130272270/lazuwivit-purilififiveg-jidogolukag.pdf
    • http://davidcarlbloom.net/uploads/1/3/0/6/130639535/nerexador.pdf
    • http://hostmaster.phyllisbeckkatz.com/uploads/1/3/0/9/130969916/zuzuxukokajufotej.pdf
    • http://redmethod.net/uploads/1/3/0/6/130604421/putan.pdf
    • http://nkbblockchain.com/uploads/1/3/0/4/130483809/voxiwezuvuxelugizol.pdf
    • http://caninecocktailpawty.com/uploads/1/3/0/5/130543784/6337d276.pdf
    • http://www.lorealcarson.com/uploads/1/3/0/8/130813269/1268948.pdf
    • http://sherlockhomeless.com/uploads/1/3/0/6/130603948/82693.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006aab.bin
5531a8d1c5093f1e61612e253789bad0a89cc317b9e46d564abccd4aeff8d776
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AAB 7832 bytes
font_01_sfnt_off00008951.bin
d907c570f1f8f2d62f38d7529dbf77de46ca3a1917ec53aca7a78bae59874b04
pdf-font-stream PDF embedded font (sfnt) at offset 0x8951 2616 bytes