Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f1e071e42e6279d…

MALICIOUS

PDF

38.7 KB Created: 2020-06-21 12:41:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b94df351f59f9ab44125c691557e459d SHA-1: 44235ac148d50e687b9900b09b9515dd9e1e46dd SHA-256: 3f1e071e42e6279d5d0aabb5c192d32cb2b73b9f255f8394da8376fd3a11ad4a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous external links, a common tactic for SEO spam and phishing. The document body suggests a lure related to 'Company aptitude test papers with answers', which is likely a pretext to encourage users to click on the embedded malicious URLs. The PDF_SEO_LINK_FARM heuristic indicates a large number of links, many of which are numeric slugs, further supporting the malicious intent of distributing traffic to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://karma.onlinevanstart.nl/uploads/1/3/0/8/130814831/130814831.html#company+aptitude+test+papers+with+answers
    • http://mckinneypaintingservice.com/uploads/1/3/1/3/131380258/b6d450b427f302.pdf
    • http://wtfarm.me/uploads/1/3/0/7/130776702/zapezelovatugotisaju.pdf
    • http://marianhuberart.com/uploads/1/3/0/5/130588203/gimuvukotuduxefiw.pdf
    • http://oceanorganicsnj.com/uploads/1/3/0/6/130620482/1c138edf333c.pdf
    • http://mycastlemanagement.com/uploads/1/3/1/4/131437649/vadatelisamexi-widudapigav.pdf
    • http://codeoftheconqueror.com/uploads/1/3/0/3/130379307/7041723.pdf
    • http://portpearleroysters.com/uploads/1/3/0/6/130604616/tijevurapikil_fowiravatixozi.pdf
    • http://nickbutler.co/uploads/1/3/1/6/131637374/gezupixejitipedened.pdf
    • http://nourishingbusinesssolutions.com/uploads/1/3/0/6/130621645/6830150.pdf
    • http://full.juanitaandtherabbit.com/uploads/1/3/1/3/131379262/410481b31bbf08.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000059e0.bin
c3f653cb9d5ff5e82f1f436be0def272e6dc95bdb15da1ca71dd2767c84b1f5b
pdf-font-stream PDF embedded font (sfnt) at offset 0x59E0 5268 bytes
font_01_sfnt_off00006ba4.bin
e64d1ce82426cb547ebb1b406595a6a6648085940e0a6b94a09d1003141fcc05
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BA4 10292 bytes