Malicious PDF — malware analysis report

Static analysis result for SHA-256 44f001780584461c…

MALICIOUS

PDF

41.6 KB Created: 2020-04-23 05:48:20 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ba7612d3817495aa61eb77978463f3b0 SHA-1: c930a93c435d4391350e3b9920f589ccb230648a SHA-256: 44f001780584461ccc59dd54e1d6dfce72891912547903836248aa8e2ab9087c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to other PDF files hosted on various domains, indicative of a link farm. The primary heuristic identified a link to 'onpointesigns.com', which appears to be part of this malicious infrastructure. The ML classifier strongly supports the malicious nature of this PDF. No scripts were extracted, and the document body was heavily obfuscated, preventing a deeper analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://onpointesigns.com/uploads/1/3/1/3/131384589/131384589.html#string+java+format+date
    • http://wholehousellc.com/uploads/1/3/0/8/130874058/wagironemivoxo.pdf
    • http://farcryvideo.com/uploads/1/3/0/6/130604821/9919643.pdf
    • http://superioriphonerepair.com/uploads/1/3/1/1/131163956/6705450.pdf
    • http://firstheaven.net/uploads/1/3/0/6/130640078/42c5944606698.pdf
    • http://totahr.com/uploads/1/3/0/8/130813510/899779.pdf
    • http://ruedasdeinnovacion.com/uploads/1/3/0/2/130274330/2600424.pdf
    • http://acclaimedpropertymanagement.com/uploads/1/3/1/4/131453332/6523952.pdf
    • http://grovenamsterdam.com/uploads/1/3/0/7/130775763/wegumupubukibijena.pdf
    • http://irscems.org/uploads/1/3/0/7/130775136/ec925c8c3.pdf
    • http://nancyellenmiller.com/uploads/1/3/1/3/131381675/diboz_jeborimijuna_netuwudasewama_fenojebewakim.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e05.bin
4ec07d98eaf13e0a9fcf07ea46af71ac93f62af22b7749714d83e8c5f0a135ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E05 8780 bytes
font_01_sfnt_off00008f83.bin
d907c570f1f8f2d62f38d7529dbf77de46ca3a1917ec53aca7a78bae59874b04
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F83 2616 bytes