Malicious PDF — malware analysis report

Static analysis result for SHA-256 32348c10adf18dfb…

MALICIOUS

PDF

39.2 KB Created: 2020-05-13 20:27:51 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9b82a6f3b984b549d7c62010ba8a130b SHA-1: 5c218b16624aaacf325ad317fb587697d34446a6 SHA-256: 32348c10adf18dfb1638d35319c097eb25c3126c45a857b306ff1e14f266a4c8
152 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF file was detected as malicious by ClamAV (Pdf.Dropper.Agent-9253366-0) and an ML classifier. It contains a large number of external links, suggesting a link farm or SEO poisoning tactic. The embedded document body text, though partially corrupted, mentions 'high school incident report form', likely a lure. The primary function appears to be distributing or linking to other malicious content via these numerous URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-9253366-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-9253366-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://exevents.net/uploads/1/3/0/5/130588597/130588597.html#high+school+incident+report+form
    • http://wsnupes.com/uploads/1/3/1/8/131856636/peterizejofigutet.pdf
    • http://dmhouseofbeauty.com/uploads/1/3/0/5/130551788/nigewijafonu.pdf
    • http://acfsystems.net/uploads/1/3/0/6/130640190/76cfc5e044.pdf
    • http://wnyfundraising.com/uploads/1/3/0/6/130621985/pepodimurova.pdf
    • http://aussieparamedic.com/uploads/1/3/1/3/131379115/7077996.pdf
    • http://eastprairiemethodists.com/uploads/1/3/0/6/130604497/buxovebojozulufuv.pdf
    • http://nomago.com/uploads/1/3/0/7/130775701/guzizivokogegojogo.pdf
    • http://drumschoolkevinsmal.com/uploads/1/3/1/3/131398235/wojazun.pdf
    • http://fridaywebdesign.nl/uploads/1/3/0/6/130639074/fisivepak.pdf
    • http://slayerwasp.com/uploads/1/3/0/4/130478831/1420f92.pdf
    • http://dtpropertiesnc.com/uploads/1/3/1/3/131381326/pejiwate.pdf
    • http://precisionsecurity.org/uploads/1/3/0/4/130489572/mifomazalo.pdf
    • http://alexpepstein.com/uploads/1/3/0/9/130969072/648cec168d.pdf
    • http://makyarias.com/uploads/1/3/0/4/130483045/xemasofi-vamexawekeka-pilanowepizawi-vifekutimi.pdf
    • http://pauljoelson.com/uploads/1/3/0/6/130620293/d59a3a1.pdf
    • http://domainspremier.net/uploads/1/3/0/4/130483193/8736881.pdf
    • http://southjerseytea.com/uploads/1/3/0/7/130738527/jopumi_wabezefafa_zoxatapomuboze_vagizekup.pdf
    • http://politicalpaige.net/uploads/1/3/0/6/130603985/xebavigike.pdf
    • http://jeannette-gems.com/uploads/1/3/0/5/130551177/f7740.pdf
    • http://rehadfurniture.com/uploads/1/3/1/3/131379118/5130408.pdf
    • http://canadacartalk.com/uploads/1/3/0/8/130814168/31e1560463050.pdf
    • http://stonepro.org/uploads/1/3/1/3/131383330/sireronajo-pawatuwi-sedinolodix.pdf
    • http://fairytaleballet.com/uploads/1/3/1/4/131438187/nawalej.pdf
    • http://drumscho
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f89.bin
a292cbb7c27527f1751ee45dc2c6a8526450765faca7de44fc4880284f9e0c05
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F89 9660 bytes