Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d2a808bde3982d1…

MALICIOUS

PDF

41.8 KB Created: 2020-06-16 13:49:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b933e19b0784cb9d781b0853eb8b7a5e SHA-1: bf780f3434d64ddfc584566fd96cb787535679a1 SHA-256: 1d2a808bde3982d1e89067939348b2086a04ba4251aa3f7cdb285360b74290b3
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, many of which point to similarly structured URLs on different domains. This is indicative of a link farm or a mechanism to distribute malicious content. The ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves redirecting users to potentially harmful websites through these embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://crgbridgeportcommercecenter.com/uploads/1/3/0/6/130604446/130604446.html#women+arm+weight+exercises
    • http://drjuby.net/uploads/1/3/0/4/130483759/xutebet.pdf
    • http://hawthornsuiteshotel.com/uploads/1/3/0/4/130488223/gasokivobevu.pdf
    • http://yfpa.info/uploads/1/3/0/6/130639551/sipapazifiwijibuz.pdf
    • http://northamericancommunicationscorp.com/uploads/1/3/1/3/131383665/49d9ddd6c.pdf
    • http://mx.rvescue.com/uploads/1/3/1/3/131379253/fesamixodew-nukubexu-josevefotofuna.pdf
    • http://youthofukrainephoenixproject.com/uploads/1/3/0/3/130323302/6316250.pdf
    • http://stevelsmith.com/uploads/1/3/1/4/131453068/29f38658f8eb9.pdf
    • http://cutebernedoodles.com/uploads/1/3/0/6/130605306/2713272.pdf
    • http://counterblaze.com/uploads/1/3/0/7/130775658/fobewo.pdf
    • http://bicyclexplorers.com/uploads/1/3/1/8/131872149/440067.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000794e.bin
f512cc656d4bb41db403ce4b010e9fd18f4244d1431f9ee40c23a7494d97f438
pdf-font-stream PDF embedded font (sfnt) at offset 0x794E 10292 bytes