Malicious PDF — malware analysis report

Static analysis result for SHA-256 2800cee116f52fc0…

MALICIOUS

PDF

54.9 KB Created: 2020-05-19 22:07:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 059c0735c4d9d667475595b2f277ba3d SHA-1: 8bed5d853eddf67cdc67c6375cc6fafc721af3bb SHA-256: 2800cee116f52fc08e521502dbc88b2c4857430efde118b910089d8962744de1
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection to malicious sites. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body contained metadata and garbled text, providing no direct user-facing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://organicscoops.org/uploads/1/3/0/6/130622002/130622002.html#karaoke+500+milhas
    • http://evangelizeme.com/uploads/1/3/0/6/130639815/5011763.pdf
    • http://bonvivantsdc.com/uploads/1/3/1/3/131398576/6861055.pdf
    • http://amandadellconsulting.com/uploads/1/3/0/2/130272483/wasoropakipafosilet.pdf
    • http://streetsoccer945.org/uploads/1/3/0/7/130776324/kefes_derasosaxatiwo.pdf
    • http://nwicmensbasketball.org/uploads/1/3/0/4/130489075/682ea2da79cc41.pdf
    • http://hendersonpoolandspa.com/uploads/1/3/0/5/130539341/e5f6e3df8.pdf
    • http://technosphereinnovation.com/uploads/1/3/0/2/130270887/dukulaze_tazik_viwasimuwi_lebetorisen.pdf
    • http://metairiewoodfloors.com/uploads/1/3/0/7/130775659/tavujetopa-rojap.pdf
    • http://aubonvin.shop/uploads/1/3/0/7/130775806/jofipuk_jakidobox_verepuzegosi.pdf
    • http://propelautomotive.com/uploads/1/3/0/5/130539049/tanetabebete.pdf
    • http://palmettobeach.net/uploads/1/3/0/5/130541103/6976260.pdf
    • http://socialtradingschool.com/uploads/1/3/1/4/131483068/b433d7f4849941.pdf
    • http://jdbikerstuff.com/uploads/1/3/1/3/131380836/2e20db9c884d.pdf
    • http://anne-g.com/uploads/1/3/0/6/130604205/9301655.pdf
    • http://affiliatedtattoofamily.com/uploads/1/3/0/5/130588551/mugilib.pdf
    • http://crystalshine.info/uploads/1/3/0/7/130776006/titisasenagotesoni.pdf
    • http://theshands.com/uploads/1/3/0/3/130379527/vifuzip.pdf
    • http://fournetlaw.com/uploads/1/3/1/6/131637255/kodew.pdf
    • http://bridgegames.co/uploads/1/3/0/3/130313468/24487bc040ad477.pdf
    • http://smithfieldhousingauthority.org/uploads/1/3/0/4/130478360/229c31442a.pdf
    • http://osoyoosmarine.com/uploads/1/3/0/7/130775551/nirujubedinoton-xajalekanafe.pdf
    • http://exoticbulliessale.com/uploads/1/3/1/1/131164437/fitofo.pdf
    • http://ttrgi.org/uploads/1/3/0/3/130313411/ludusedexafe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000919f.bin
d90d58fedfc288ea93e2e7b6203b2a0dab8fd0eb601a6a6fa2df5d97258fbd99
pdf-font-stream PDF embedded font (sfnt) at offset 0x919F 5568 bytes
font_01_sfnt_off0000a4f6.bin
181f077083f669084d835f4c8ed76643fecb128188253744f1f74d99d27fedfb
pdf-font-stream PDF embedded font (sfnt) at offset 0xA4F6 13912 bytes