Malicious PDF — malware analysis report

Static analysis result for SHA-256 337740e6fac689e6…

MALICIOUS

PDF

52.2 KB Created: 2020-03-28 09:43:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: be08d737b1a4cfd9a4828d25841627be SHA-1: 677510597ea9238555c4eb5381df0ab4f2d310da SHA-256: 337740e6fac689e67b026c9f129c11d4ccaf5d0ee7b363c884cd0581f31967ef
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document exhibits characteristics of a link farm, containing a large number of external links to various domains. The primary heuristic 'PDF_SEO_LINK_FARM' indicates that the PDF is designed to generate a significant number of outbound links, likely for SEO manipulation or to distribute traffic to potentially malicious sites. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://joyofphysics.com/uploads/1/3/0/4/130488273/130488273.html#let+go+album+tracklist
    • http://meaganharringtondiaz.com/uploads/1/3/0/6/130604533/1735610.pdf
    • http://mx.skipcoryell.com/uploads/1/3/0/6/130604888/4354760.pdf
    • http://www.earthboundblackbird.com/uploads/1/3/0/7/130739048/mumuforog-ziruwavugi-raduma-zomuxosonozek.pdf
    • http://nathanbohachvibes.com/uploads/1/3/0/7/130776874/mibiraxidiku_porugatod_magomemume_sivitovatubon.pdf
    • http://poetrybattlescommunity.com/uploads/1/3/0/7/130775171/toboverojowefop.pdf
    • http://emiliasdesigneremporium.com/uploads/1/3/1/1/131164016/2642133.pdf
    • http://webdisk.janajedermann.com/uploads/1/3/0/8/130813835/b8898edc8a4d4c0.pdf
    • http://hispanocenter.com/uploads/1/3/0/5/130539251/7612100.pdf
    • http://www.splatterdome.com/uploads/1/3/0/9/130969576/bitatovopopawezu.pdf
    • http://creativemindsa2z.shop/uploads/1/3/0/5/130588565/1ed7a70990804c1.pdf
    • http://earthangelofchrist.org/uploads/1/3/0/8/130874378/zawip.pdf
    • http://tylerdsmith.org/uploads/1/3/0/4/130435658/4055815.pdf
    • http://laventanadecali.com/uploads/1/3/0/6/130621741/fipukipukiz_wexabebusimivug_rebarobureme.pdf
    • http://angelsondeathrow.com/uploads/1/3/0/4/130476908/1375444.pdf
    • http://erotihub.com/uploads/1/3/0/2/130272355/d96c5b32.pdf
    • http://ineedexercise.com/uploads/1/3/0/6/130604363/4315798.pdf
    • http://tgpaintersmaine.com/uploads/1/3/0/6/130604333/jojarifegabeza.pdf
    • http://cooloasistires.com/uploads/1/3/0/7/130738684/jijitituk_rapuzewibakerix_xusilis.pdf
    • http://ghz.one/uploads/1/3/0/8/130873941/nalugisevemu.pdf
    • http://digitalparentconsulting.com/uploads/1/3/0/5/130539718/vapobeg.pdf
    • http://ya-amar.com/uploads/1/3/0/6/130605071/4371559.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009679.bin
cbc342171c40a6f76060085f67816d9fafe37e3f812ae2dfdf941fe7d587cf92
pdf-font-stream PDF embedded font (sfnt) at offset 0x9679 8928 bytes
font_01_sfnt_off0000b8df.bin
3d48a4a0171bc8984a9d002c5b63de59358ba63bf648af7a75746ee17eec0d99
pdf-font-stream PDF embedded font (sfnt) at offset 0xB8DF 2192 bytes