Malicious PDF — malware analysis report

Static analysis result for SHA-256 14123c4881490391…

MALICIOUS

PDF

35.6 KB Created: 2020-04-24 16:21:40 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a5e69c235d2028f45aa5a79e9ca7436f SHA-1: f0b06d5a676fb9c10e946d7407b65e9efa24239a SHA-256: 14123c4881490391d58be8d19788528c6ccf88c7827d492331326b4389483ec0
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which follow a pattern indicative of a link farm or SEO spam. The primary link points to a deceptive HTML page, suggesting a phishing or malicious redirection attempt. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://baufinanz-rheinmain.net/uploads/1/3/0/7/130775198/130775198.html#the+crucible+act+3+analysis+answers
    • http://pilgrimsailing.com/uploads/1/3/0/2/130270855/devari_luxofajat_pumara_zuzazasexalij.pdf
    • http://afleroux.com/uploads/1/3/1/3/131379189/84d53eeb606ec.pdf
    • http://leadingwomenministries.org/uploads/1/3/0/6/130603966/6fdc9.pdf
    • http://tegnp�l�ring.dk/uploads/1/3/0/8/130814387/befudoziz.pdf
    • http://misquotedbible.com/uploads/1/3/0/5/130589040/43f5c3f514.pdf
    • http://we-need-jesus.org/uploads/1/3/1/0/131070387/xisoworaval.pdf
    • http://amyswicked.net/uploads/1/3/0/6/130620989/1095c1d26b0e.pdf
    • http://miracleinabucket.com/uploads/1/3/0/8/130874475/gejewenaluf-rekod.pdf
    • http://hostalsaltillo.com/uploads/1/3/1/1/131164358/8279238.pdf
    • http://scotiamaintenance.com/uploads/1/3/1/3/131384028/wuvalefibulu.pdf
    • http://flagshiplaw.net/uploads/1/3/1/4/131437102/wokenubapaxagivuv.pdf
    • http://pointandstretch.org/uploads/1/3/0/5/130544232/topimekoxowosopir.pdf
    • http://dgh.nyc/uploads/1/3/0/3/130313495/bipag.pdf
    • http://diamondlospoblanos.com/uploads/1/3/1/4/131438694/3498638.pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007217.bin
0d2615d7f42f6d0ce9fc09f08f8c32a59fffe8b5c43b71ff518f12d74f992055
pdf-font-stream PDF embedded font (sfnt) at offset 0x7217 7772 bytes