Malicious PDF — malware analysis report

Static analysis result for SHA-256 f284c0d20d584569…

MALICIOUS

PDF

51.1 KB Created: 2020-04-27 19:47:02 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6) First seen: 2026-05-07
MD5: 08ede997df0024032c71fe9b2ce74457 SHA-1: cc75f09e35962bcc5e1b37b257b1197054083ed5 SHA-256: f284c0d20d584569d876cb7aab3a72e5e21634d0753368955f610b9d91d0f428
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.003 Windows Command Shell

The PDF file contains a large number of external links, many of which point to domains that appear to be part of a link farm. The 'SE_LOLBIN_RUN_COMMAND' heuristic indicates that the document contains instructions for executing Windows scripting tools, suggesting an intent to download and execute further payloads. The document body, though heavily obfuscated, contains text related to sheet music, which is likely a lure to encourage users to click the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9963

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://movimientomexicano2018.org/uploads/1/3/0/9/130969796/130969796.html#arabesque+sheet+music+piano+pdf PDF link annotation
    • http://claypottsbuildingservices.net/uploads/1/3/0/7/130740003/5016298.pdfIn PDF document text
    • http://mscproofs.com/uploads/1/3/0/8/130814401/442578fd.pdfIn PDF document text
    • http://wificonnectedappliances.com/uploads/1/3/1/4/131437402/3770997.pdfIn PDF document text
    • http://datafluxvoicevideodatasolutions.com/uploads/1/3/1/3/131379699/4331c643f1681.pdfIn PDF document text
    • http://tecnocamp.academy/uploads/1/3/0/6/130621700/712411.pdfIn PDF document text
    • https://musescore.ssiIn PDF document text
    • https://musescoreIn PDF document text
    • https://musescore.netIn PDF document text
    • https://www.1000000000000000055511151231257827021181583404541015625},{In PDF document text
    • https://musescore.1In PDF document text
    • https://musescore.200000000000000011102230246251565404236316680908203125In PDF document text
    • https://musescore.com%2Fuser%2F29813359%2Fscores%2F5735057In PDF document text
    • https://musescore.LearnIn PDF document text
    • https://musescore.jpg?cache=0In PDF document text
    • https://musescore.mp3?revision=1571923922&no-cache=1588006020In PDF document text
    • https://musescore.01000000000000000020816681711721685132943093776702880859375In PDF document text
    • https://musescore.mid?revision=1571923922&no-cache=1588006020In PDF document text
    • https://musescore.05000000000000000277555756156289135105907917022705078125},{In PDF document text
    • https://musescore.com/user/29813359In PDF document text
    • https://musescore.com/static/musescore/scoredata/gen/7/5/0/5735057/976de5766b8d3cb6614348d174bb1b6280175d6d/In PDF document text
    • https://musescore.com/static/musescore/scoredata/gen/7/5/0/5735057/976de5766b8d3cb6614348d174bb1b6280175d6d/score.com/user/29813359/scores/5735057In PDF document text
    • https://musescore.com/static/musescore/userdata/cover/8/6/9/29813359.ssiIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009966.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9966 10772 bytes
SHA-256: baf0245ea290ba1c19f402331c8c2d6d960034c9544574af20abd4eeed984b69