Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c3bd317757e53fe…

MALICIOUS

PDF

124.4 KB Created: 2020-03-30 17:54:43 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9d59b9b617285db5c38b019b2ac671e5 SHA-1: 70382c1587eaf32c622f7ebc482ef2abe432db20 SHA-256: 8c3bd317757e53fe447a38524994b4d90e8aa70d5d928bad734568af9910be19
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous external links, a technique often used for SEO manipulation or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness. No scripts were extracted, and the document body is heavily obfuscated, but the presence of a link farm suggests an attempt to drive traffic to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xrossingborders.net/uploads/1/3/0/5/130544953/130544953.html#etiologia+de+diabetes+mellitus+tipo+1+y+2+en+el+paciente+anciano
    • http://wellfleetfallfestival.com/uploads/1/3/0/9/130969965/wenimuzokemako.pdf
    • http://outreachchemistrycloud.com/uploads/1/3/0/3/130323161/lekepofogepubik.pdf
    • http://fictionalbookshop.com/uploads/1/3/0/4/130476047/e2653330.pdf
    • http://simply-beautiful-online.com/uploads/1/3/1/0/131069992/fudetanopolis.pdf
    • http://www.ourserenityhouse.net/uploads/1/3/0/4/130435532/pobesuraxakeko_gutamepiwoxelav_defemivugi.pdf
    • http://luvgnv.com/uploads/1/3/0/9/130969483/90039d07eb46f.pdf
    • http://noblescounseling.com/uploads/1/3/0/3/130323328/sagefoluwap.pdf
    • http://adogslifeoxon.com/uploads/1/3/0/7/130776603/6825164.pdf
    • http://mascarathatworks.com/uploads/1/3/0/4/130489175/d5f2fe927be514.pdf
    • http://stolani-shoes.com/uploads/1/3/0/7/130738792/tugebu_xazulojum.pdf
    • http://mytexasautoholdings.com/uploads/1/3/0/7/130740049/5957447.pdf
    • http://thelagoonsedge.com/uploads/1/3/0/7/130740130/padutedivu-fipaperira.pdf
    • http://www.blueskychildrenstheatre.com/uploads/1/3/0/4/130483757/rexikumefivabi.pdf
    • http://stevenlwright.family/uploads/1/3/0/7/130740060/34d7f7bcd.pdf
    • http://cld.nu/uploads/1/3/0/6/130620159/luxom_visusanakizebek.pdf
    • http://toyotagarut.id/uploads/1/3/0/7/130776063/mazewi_saroxobuguk_mipufazarelu_gezijet.pdf
    • http://avalonbarbequecompany.com/uploads/1/3/0/7/130775588/1417124.pdf
    • http://iicforsuccess.net/uploads/1/3/0/3/130313786/5810daff1.pdf
    • http://mystatenislandlocksmith.com/uploads/1/3/0/5/130551491/fanawinivemus-tezidadaz-wimedasubu-vusuwaruzape.pdf
    • http://harvestcityworship.com/uploads/1/3/1/3/131380811/wunanifepizirawaje.pdf
    • http://www.ellenanhari.nl/uploads/1/3/1/1/131164027/jedodeget.pdf
    • http://knightrenovations.com/uploads/1/3/0/2/130289532/388133.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019a2e.bin
889a7786cda5547881e05235bc89d9fad3aed42fd550d158109995fe10e070a8
pdf-font-stream PDF embedded font (sfnt) at offset 0x19A2E 10404 bytes
font_01_sfnt_off0001bee6.bin
9ea54935d53598998e5fef336d9b67a5b6b32ec95de8d6782611390f29316c5e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BEE6 3536 bytes
font_02_sfnt_off0001cb30.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CB30 16036 bytes