Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b0ce92e2c738c80…

MALICIOUS

PDF

38.3 KB Created: 2020-05-23 21:05:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9cb6277636c171c8b1a23b9c72d8ebad SHA-1: b672f7732827dfb5144da648f765dad4eff5eadf SHA-256: 8b0ce92e2c738c80c7ce569cec3c42621882d8691fb6e97e1562a708fa26e3d4
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, many of which point to other PDF files hosted on similar domains. The document body text is largely garbled but includes references to 'manual de exegese do antigo testamento pdf' and the wkhtmltopdf application, suggesting a lure to download a document. The ML classifier strongly indicated maliciousness, and the PDF_SEO_LINK_FARM heuristic confirms a large number of external links designed to appear as legitimate documents.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9928

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sam-tisher-senio-1.rominastiebenphotography.com/uploads/1/3/1/6/131607662/131607662.html#manual+de+exegese+do+antigo+testamento+pdf
    • http://landscapeconstruction.org/uploads/1/3/0/6/130604708/58a6ddd7e3b7c.pdf
    • http://chiefmahoo.com/uploads/1/3/1/3/131378898/376346.pdf
    • http://rainbowkaleki.org/uploads/1/3/1/3/131380612/640bc3.pdf
    • http://theminacmansion.com/uploads/1/3/0/2/130271244/5163300.pdf
    • http://stellamacdonaldautism.com/uploads/1/3/1/6/131606588/kinonadolisepen.pdf
    • http://gentlepawstherapypet.org/uploads/1/3/0/5/130588540/c23ed7148be07a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006514.bin
f3e59606b2d3a0285a504111d9a15357ddec91aeaa627f5fc6c8f84f14ab26a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x6514 13404 bytes