Malicious PDF — malware analysis report

Static analysis result for SHA-256 d07772098c785691…

MALICIOUS

PDF

46.6 KB Created: 2020-03-29 04:41:14 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: dad9be3c27d4fe541a4609ef4392dd3a SHA-1: 4cdd54ea8d4310792bac4068de3ebf3d4de31f62 SHA-256: d07772098c7856914d0a7f4286103694314de3e4e9ecfaa1dc964e1311f5858d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which are numerically or generically named, pointing to a network of websites. The document body, though corrupted, contains text related to 'weight loss workout plan pdf' and the tool 'wkhtmltopdf', suggesting a lure to a content farm or phishing site. The ML classifier strongly flagged this PDF as malicious, indicating a high likelihood of malicious intent behind the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://multistreams.com/uploads/1/3/1/4/131438538/131438538.html#weight+loss+workout+plan+pdf
    • http://mythfreefinancial.com/uploads/1/3/0/8/130815726/1273604.pdf
    • http://onewebday.net/uploads/1/3/0/7/130738836/3975624.pdf
    • http://actorheadsorlando.com/uploads/1/3/0/4/130476066/zopaxagurizob.pdf
    • http://eakinmd.com/uploads/1/3/0/4/130478174/fuzekuxu.pdf
    • http://gotchacomics.com/uploads/1/3/0/6/130640139/3ba4c2dcf6a.pdf
    • http://hotrodinvestments.com/uploads/1/3/1/0/131070998/vilafeline.pdf
    • http://wallinba.com/uploads/1/3/0/3/130313673/27ca9161.pdf
    • http://bogolist.com/uploads/1/3/0/8/130874409/lujesol-weremogasas-javimadub-junisimopapo.pdf
    • http://empressloungeboutique.com/uploads/1/3/0/5/130544541/fagakolumulun.pdf
    • http://seartiststudio.com/uploads/1/3/0/8/130873826/pusut.pdf
    • http://whitesflooring.com/uploads/1/3/1/4/131406248/jizuj.pdf
    • http://rowdybartending.com/uploads/1/3/0/6/130639776/2da724.pdf
    • http://dr-pratt-emotional-mastery.com/uploads/1/3/0/6/130620657/8546822.pdf
    • http://www.jrmfash.com/uploads/1/3/0/5/130551140/xufutakamimi-papagerezumo.pdf
    • http://carlsbadcleaningservices.com/uploads/1/3/0/8/130814346/tifuloxukejumeb-pasad-wukopeg-jajewewitosub.pdf
    • http://dominicsaunders.com/uploads/1/3/1/1/131163836/cbbf5d54027b.pdf
    • http://essentialritualsandwellness.com/uploads/1/3/0/6/130620781/xilimesedunopu-togakegogikopuk-zeredomaze.pdf
    • http://tonyvalado.com/uploads/1/3/0/2/130273578/3833463.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008be5.bin
3862f628cb4af732db9424f84053f1fd33823e99cf3472340452ec6e4272bde9
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BE5 8760 bytes