Malicious PDF — malware analysis report

Static analysis result for SHA-256 0eaf406310d8431a…

MALICIOUS

PDF

24.9 KB Created: 2020-05-11 18:38:40 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5d4c6542020f2e14aebb0b46dc4de1d9 SHA-1: 10227a63d1dd9fc5a26b6bec85254565a7c36210 SHA-256: 0eaf406310d8431a7e739a6836052621a3b433ef5d4d409eb1244eca55ba2058
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to other PDF files hosted on various domains, indicating a link farm or SEO spam campaign. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern involves directing users to a network of potentially malicious or deceptive content via these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9770

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://solidrockhomecareassistance.com/uploads/1/3/1/6/131607019/131607019.html#noughts+and+crosses+game+template
    • http://landlcollaborations.net/uploads/1/3/1/4/131437436/fajegufotu.pdf
    • http://milosgiannoulishotel.gr/uploads/1/3/0/3/130313612/2320338.pdf
    • http://jefffraskamusic.com/uploads/1/3/0/3/130323516/kabarubafowojeripod.pdf
    • http://myinspirationspace.com/uploads/1/3/0/6/130604348/9489114.pdf
    • http://bunnyslopesports.com/uploads/1/3/1/3/131380847/2084174.pdf
    • http://veteranautosales.org/uploads/1/3/0/5/130551604/puwetapebuzat.pdf
    • http://olgarenteria.com/uploads/1/3/0/4/130488179/5911890.pdf
    • http://allin1renovations.com/uploads/1/3/0/5/130548039/pumunaxuzo.pdf
    • http://ellierusinova.com/uploads/1/3/0/6/130604756/aed820.pdf