Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f3b9ba52ddcaeda…

MALICIOUS

PDF

36.8 KB Created: 2020-04-08 21:17:55 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a1dfc50374d01bbd56e2253287d0357d SHA-1: cace594fcb168a51c6d79164b94a2117a8dc2db0 SHA-256: 3f3b9ba52ddcaeda3261c14fac6f0673de04c84877e4ee2688cdfc4608f26052
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links to other PDF files hosted on various domains, a technique often used for SEO link farming or to redirect users to malicious content. The ML classifier also flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact payload or intent beyond the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://joyofphysics.com/uploads/1/3/0/6/130605256/130605256.html#stellaris+console+edition+multiplayer
    • http://nirvanatails.org/uploads/1/3/0/8/130874377/vosal_lasowowore.pdf
    • http://sacredsummitchocolate.com/uploads/1/3/0/6/130639166/digufuvonuvejula.pdf
    • http://truebluewealth.com/uploads/1/3/0/4/130491703/sezojite-sevusebofi.pdf
    • http://remotewurk.com/uploads/1/3/0/6/130639278/tilerukijifikase.pdf
    • http://democracyevolved.org/uploads/1/3/0/8/130814040/1029426.pdf
    • http://fatrocktile.net/uploads/1/3/0/5/130550679/jesubaw_detizibaxaduba_bexawileb_mabukozel.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000664b.bin
ae41268e42688850f55aa19440a6fcf8f85192f6ad7e4f17cd3df037565a3bb4
pdf-font-stream PDF embedded font (sfnt) at offset 0x664B 7796 bytes