Malicious PDF — malware analysis report

Static analysis result for SHA-256 1aa7006a01d34c3f…

MALICIOUS

PDF

40.9 KB Created: 2020-03-26 03:14:55 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: bc46311ce8ed55b9efaa7d1098a2db7e SHA-1: 8f4dc3edf8094bbb5688908f08171b953cf65d55 SHA-256: 1aa7006a01d34c3f48e21b222d4ff005e0d1de6af7cbd7419ea03869a5ccfb89
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

This PDF file was identified as malicious by an ML classifier. It contains a large number of external links, many pointing to PDF files with numeric slugs, indicative of a link farm or SEO manipulation tactic. The primary URL, http://bahamasaugustllc.com/uploads/1/3/0/3/130379118/130379118.html#valores+de+coeficiente+de+rozamiento+estatico+y+cinetico, suggests the document is disguised as a technical paper to encourage clicks.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bahamasaugustllc.com/uploads/1/3/0/3/130379118/130379118.html#valores+de+coeficiente+de+rozamiento+estatico+y+cinetico
    • http://genevievejohnson.com/uploads/1/3/0/7/130740483/6855792.pdf
    • http://server.scscal.com/uploads/1/3/0/8/130814176/gosetuz.pdf
    • http://aboveandbeyond.org.za/uploads/1/3/0/8/130874600/6a3296ede2a.pdf
    • http://countryandeasylistening.net/uploads/1/3/1/1/131164272/pimirete.pdf
    • http://band-ems.org/uploads/1/3/0/6/130639941/zobuxowevufidos.pdf
    • http://bluegoldlacrosse.com/uploads/1/3/0/5/130588596/sumasofus-zusuf-dekoju.pdf
    • http://www.butterinvictor.com/uploads/1/3/0/5/130551604/muxizejipu.pdf
    • http://jungkyookimkorea.com/uploads/1/3/0/3/130323143/8916705.pdf
    • http://www.redrobynsnest.com/uploads/1/3/0/2/130289535/3830223.pdf
    • http://nblbball.com/uploads/1/3/0/6/130639852/nobikerajebologazotu.pdf
    • http://kristinw.com/uploads/1/3/0/7/130738946/23fbe.pdf
    • http://triplehcastle.com/uploads/1/3/0/5/130550976/zorabewoz.pdf
    • http://xalbador.co.za/uploads/1/3/0/5/130588405/xogugasexavo.pdf
    • http://kvardek.com/uploads/1/3/0/5/130544384/9330132.pdf
    • http://millikenentertainment.net/uploads/1/3/0/2/130272877/niroj.pdf
    • http://leads2freedom.com/uploads/1/3/0/7/130776726/fifosebivare_jexikuva.pdf
    • http://www.thepentaxpioneer.com/uploads/1/3/0/9/130969241/zofulosisaw.pdf
    • http://islandclubreccenter.com/uploads/1/3/0/7/130738548/webuxu.pdf
    • http://palomagrapevinetx.com/uploads/1/3/0/2/130272955/winef_nofisuwi_wedam.pdf
    • http://boojeeplustique.com/uploads/1/3/0/6/130639751/jaradamatowi_losipegej_gekana.pdf
    • http://joyfulearthsoaps.net/uploads/1/3/0/6/130622005/wagimakapefefawoka.pdf
    • http://bhuoconversion.com/uploads/1/3/0/5/130551142/3389562.pdf
    • http://houseboat.site/uploads/1/3/0/5/130543840/cd8320cd4dac99e.pdf
    • http://mermaidazora.com/uploads/1/3/0/4/130478307/rozewa.pdf
    • http://mermaidazora.com/uploads/1/3/0/4/130478307/ro
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007650.bin
74385b110b8e62369ea6082c9ca0ad495f3521e9693bc9f9e895df7f8f827db6
pdf-font-stream PDF embedded font (sfnt) at offset 0x7650 7820 bytes