Malicious PDF — malware analysis report

Static analysis result for SHA-256 5128aaa5cbc00a87…

MALICIOUS

PDF

130.9 KB Created: 2020-03-23 09:53:41 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a09963386969740242819b4d059b91f4 SHA-1: 6551b0d71af9cbbe0afbb85010742f5abec7b535 SHA-256: 5128aaa5cbc00a8754c7d7e614bc1dd1511f23e3b18991a6d5e0a54dae8ee858
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The primary URL, http://1corin1531.com/uploads/1/3/0/2/130274281/130274281.html#the+rocket+ray+bradbury+theme, is part of this link farm. This suggests a tactic to manipulate search engine results or to host a large number of potentially malicious landing pages. No scripts were extracted, limiting the analysis of direct payload execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://1corin1531.com/uploads/1/3/0/2/130274281/130274281.html#the+rocket+ray+bradbury+theme
    • http://e-y-o-6.com/uploads/1/3/0/4/130488295/nuvenisawizora.pdf
    • http://thebirthbee.com/uploads/1/3/0/6/130604101/zadapavuxogaxugofo.pdf
    • http://www.divyanshuabhellochandaniii.com/uploads/1/3/0/8/130874362/4e1239b.pdf
    • http://mimiscoffeehouseofhardwick.com/uploads/1/3/0/4/130483309/pisajumexozovi.pdf
    • http://jaclynkaloczi.com/uploads/1/3/0/5/130538902/7010499.pdf
    • http://hostmaster.blackpoolbelle.com/uploads/1/3/0/4/130483983/fotanusesu.pdf
    • http://tanahome.com/uploads/1/3/0/6/130605355/4888977.pdf
    • http://www.donatetoanimalrescue.org/uploads/1/3/0/7/130776673/3851535.pdf
    • http://minoritypodcast.com/uploads/1/3/0/4/130435561/livutezurovuzepedug.pdf
    • http://furnihack.com/uploads/1/3/0/6/130603725/370f7d8dda26ba.pdf
    • http://astoken.com/uploads/1/3/0/4/130490875/418231.pdf
    • http://afghanistanforwardus.org/uploads/1/3/0/2/130287842/reledutomonige.pdf
    • http://cpanel.onlinecreator.net/uploads/1/3/0/7/130775573/8943424.pdf
    • http://thecaveacademy.org/uploads/1/3/0/2/130273987/jinekiz_lebewexibitabo_joxanaxa_zadanu.pdf
    • http://forzaatleti.es/uploads/1/3/0/5/130541817/lavuxudikesoruj_pizedug.pdf
    • http://becomearelationshipmaster.com/uploads/1/3/0/4/130435803/9543075.pdf
    • http://trickortri.com/uploads/1/3/0/5/130551335/zofesutuzo.pdf
    • http://quartzcreeklines.com/uploads/1/3/0/6/130621128/gudodisos_patijezam_pororikubeb.pdf
    • http://bratrudag.ca/uploads/1/3/0/7/130739910/bdc7062f3e538c.pdf
    • http://shesjustamom.com/uploads/1/3/0/3/130323424/poruwutemikawudun.pdf
    • http://isfnrconf.org/uploads/1/3/0/7/130776823/1280259.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001df95.bin
9c08e53ac77946f9d8f1549218a7d19f14a7fd9837c7dc228f7fde28fa4a66a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DF95 7652 bytes