Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b501eb337ce1cfe…

MALICIOUS

PDF

28.1 KB Created: 2020-04-16 16:13:16 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: eac2fab97ad763bb90e48f43f1ba20c2 SHA-1: 7d986940916ca08bb460564b95dfd06bf3de7c91 SHA-256: 0b501eb337ce1cfecd50839f79b708e96ce366faf077fd1c09aa2da66f3f18d5
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a significant number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or a distribution mechanism for further malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9682

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://authorselves.com/uploads/1/3/1/3/131398140/131398140.html#12th+half+yearly+exam+answer+key+2018
    • http://kaitlinparker.com/uploads/1/3/0/6/130605279/5524d7160d89a4.pdf
    • http://ncmetalbuildingsdirect.com/uploads/1/3/0/4/130489909/sogolodime.pdf
    • http://elchefdelcaviar.com/uploads/1/3/0/7/130738912/ae8fee.pdf
    • http://ctmelectricinc.com/uploads/1/3/0/6/130603955/58845fb0.pdf
    • http://realsaltshop.com/uploads/1/3/0/6/130605275/deroru_rilonoro_kewakeguzefagub.pdf
    • http://gxbitcoins.com/uploads/1/3/0/3/130379475/8484239.pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005881.bin
be002582fd00a7b7d83a97caa32f48c73b91b1128dca18e9994f0f6e02119255
pdf-font-stream PDF embedded font (sfnt) at offset 0x5881 7988 bytes