Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e7f6fa583133b39…

MALICIOUS

PDF

43.5 KB Created: 2020-04-03 08:51:21 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ad0ed257b05c55f2b87c0d591985fc54 SHA-1: 727d91f71983843340fd5f099bda8e2e380b5d6a SHA-256: 1e7f6fa583133b3925a7e7d1f296df1dc16fb5caac464772320183b78f3a1d34
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to various domains, forming a link farm. The primary URL points to an HTML page with a title related to calculating net worth, likely a lure. The heuristic 'PDF_SEO_LINK_FARM' indicates a deliberate attempt to create a network of linked PDFs across multiple hosts. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sadiths.com/uploads/1/3/0/6/130639017/130639017.html#como+calcular+o+patrim%C3%B4nio+l%C3%ADquido+de+uma+empresa
    • http://pilatesbrienzseestark.com/uploads/1/3/0/2/130289163/9919222.pdf
    • http://lumenbeinghuman.com/uploads/1/3/0/4/130476786/kabupoluguvupak_fodol.pdf
    • http://painfreeretreats.com/uploads/1/3/0/8/130874180/c451efa74c69cb8.pdf
    • http://emfeduresources.com/uploads/1/3/0/5/130588272/15e49f050.pdf
    • http://bartlove.com/uploads/1/3/0/3/130379517/1705175.pdf
    • http://kb-creations.com/uploads/1/3/1/3/131379163/duvur-sejun-gisobuvulefi.pdf
    • http://nhsecurity.net/uploads/1/3/0/5/130589397/16c6850f3a9df.pdf
    • http://michaeldianne.com/uploads/1/3/0/7/130739140/1190951.pdf
    • http://schuberthackett.com/uploads/1/3/0/9/130969545/katigumad-fuxilaninidix-vikujewivu.pdf
    • http://bhbqualityassets.com/uploads/1/3/0/5/130588502/a861954cbf.pdf
    • http://1200madisonindianapolis.com/uploads/1/3/0/6/130621384/kabodajuzike_vutuxemeparewu.pdf
    • http://probair.com/uploads/1/3/0/5/130590043/sexesexuxajugat.pdf
    • http://brightriverpgh.com/uploads/1/3/0/7/130739661/4836397.pdf
    • http://topfaceboook.com/uploads/1/3/1/4/131482812/najojoro.pdf
    • http://jbabyy.com/uploads/1/3/0/6/130639221/87a2b26.pdf
    • http://atxbotanicals.com/uploads/1/3/1/3/131398164/wexigon.pdf
    • http://marketdecisionpoint.com/uploads/1/3/0/6/130621437/5296177.pdf
    • http://preciousbet.com/uploads/1/3/0/6/130604141/dofogav-minuludevag-waluw-wimapel.pdf
    • http://lizmonasky.com/uploads/1/3/0/2/130289096/1187255.pdf
    • http://mageneralconstruction.com/uploads/1/3/0/5/130541733/jazafenog.pdf
    • http://harvardcases.com/uploads/1/3/0/7/130775537/7738498.pdf
    • http://thenailgoat.com/uploads/1/3/0/9/130968968/7b3f7b3.pdf
    • http://julietbeaute.shop/uploads/1/3/0/7/130776519/7167583.pdf
    • http://olsonbd.com/uploads/1/3/0/9/130969852/kibaz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007b5b.bin
100357381ddd3f38af41865dd029047fa9d142c44b79639999913eb8965bc67d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B5B 10344 bytes