Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d72d6998366bc81…

MALICIOUS

PDF

38.4 KB Created: 2020-05-14 20:11:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a3090e889287751de3cec2c23f04266e SHA-1: 8d969939242c5a07f8b7587823cdf597b64014f4 SHA-256: 2d72d6998366bc8181b13147a37dcf9d8d5e46270becfbd26470dd941eed744c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF document exhibits characteristics of a link farm, containing a large number of external links to other PDF files hosted on various domains. The primary heuristic, PDF_SEO_LINK_FARM, indicates a deliberate attempt to create a network of linked content. The embedded URLs and the document body, though partially obfuscated, reinforce this by listing numerous PDF and HTML file paths. The ML classifier also strongly flagged this sample as malicious. The overall purpose appears to be SEO manipulation or potentially distributing further malicious payloads through the linked documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bigdsuperfoods.com/uploads/1/3/0/9/130969190/130969190.html#animation+composer+full+version
    • http://mgolocpa.com/uploads/1/3/0/3/130323896/xoxubu_jomodanapuboj.pdf
    • http://nationalnannytrainingday.com/uploads/1/3/0/7/130776394/8679015.pdf
    • http://folkochstad.se/uploads/1/3/0/8/130813846/povexedo.pdf
    • http://procomalim.com/uploads/1/3/1/4/131437350/xisodowebomiro_fimugipuzi_watilen.pdf
    • http://3ddynamics.org/uploads/1/3/0/8/130813779/virarifafewi_lumubob_napev.pdf
    • http://joyoflivingcenter.org/uploads/1/3/0/4/130488312/5475902.pdf
    • http://themelville.net/uploads/1/3/1/0/131070487/3513049.pdf
    • http://justjig1.com/uploads/1/3/0/7/130775755/0025ae7ae0c97d2.pdf
    • http://madererialacima.net/uploads/1/3/0/7/130776692/8252220.pdf
    • http://renewalleave.org/uploads/1/3/0/9/130969701/damotesom-liwunegis-luzebivogupe.pdf
    • http://trailoflifecowboychurch.org/uploads/1/3/1/3/131380265/tesilabuzenivu.pdf
    • http://eternalage.org/uploads/1/3/0/4/130488270/000f4f30c4b4b20.pdf
    • http://ccsells.com/uploads/1/3/1/3/131379420/67e469.pdf
    • http://jvnhomes.com/uploads/1/3/1/6/131606360/potubumekaga.pdf
    • http://stampedetoner.ca/uploads/1/3/0/5/130588545/7247345f58.pdf
    • http://foodtogove.com/uploads/1/3/0/7/130739492/4aee44846.pdf
    • http://michaelhollenbachpotteryandsculpture.com/uploads/1/3/0/6/130639803/2650211.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ab6.bin
69a11164fe3854348eee1a7057eed1bfa4b69c30877d759cc70543cb69af0b4c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AB6 10408 bytes