Malicious PDF — malware analysis report

Static analysis result for SHA-256 47d6c5d1cf69a526…

MALICIOUS

PDF

35.3 KB Created: 2020-04-25 14:01:05 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: aa243f57a00503a60989cc71b92c1a34 SHA-1: 054ff372950779afb4c2a14213ea5d84d0016fe0 SHA-256: 47d6c5d1cf69a5262f9a24b367ba1209db8a0ec6e9acdc5dfdaabe46f3a597d4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to other PDF files hosted on various domains. This behavior is indicative of a link farm or SEO spam technique, likely intended to drive traffic or host malicious content. The primary URL extracted, 'http://excelsignsgraphics.com/uploads/1/3/1/4/131483219/131483219.html#lending+money+contract+template+free', suggests a social engineering lure related to financial contracts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://excelsignsgraphics.com/uploads/1/3/1/4/131483219/131483219.html#lending+money+contract+template+free
    • http://connecttonature.com/uploads/1/3/0/5/130590154/50ac080e9915.pdf
    • http://dutchacrespupscom.com/uploads/1/3/0/5/130545537/7776369.pdf
    • http://stevetaboga.com/uploads/1/3/0/7/130775106/lujunuzud-josazujarakod-werones-jegusijejexapew.pdf
    • http://smarttimek9.com/uploads/1/3/0/6/130620379/lorezexenovum-givexebosusufo-vadexesekumep-budiwivefejarud.pdf
    • http://projectinnocencefreejameslucien.com/uploads/1/3/0/4/130489185/4752319.pdf
    • http://graciedavies.com/uploads/1/3/0/6/130605113/potemege_vajab.pdf
    • http://tripodcatdesign.com/uploads/1/3/1/4/131483128/6e950cf24c69ae7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063bd.bin
e8d62ee7868bfef54a808949ae0f6993a67d22ab0f71302adf35868081a7b4f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x63BD 7592 bytes