Malicious PDF — malware analysis report

Static analysis result for SHA-256 94593fb4371ec3bf…

MALICIOUS

PDF

54.6 KB Created: 2020-06-05 14:48:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a3e0ad202146131a25ce5a4cc1c7dacd SHA-1: b0517f0cb4f071f35ff35938c38524ddfdc22cee SHA-256: 94593fb4371ec3bff2d004f23f141ec82c466f3f983a891fa742278ccf492d72
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous external links, many pointing to suspicious domains, indicating a link farm or redirection strategy. The ML classifier strongly flagged this PDF as malicious. The document body, though partially corrupted, contains a URL that aligns with the suspicious external links found, suggesting a lure to a potentially malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://74-123-73-178.mgwnet.com/uploads/1/3/0/5/130551805/130551805.html#ejercicios+de+tecnologia+2+eso+resueltos
    • http://ronswalktalks.com/uploads/1/3/0/7/130776089/zakumusexomisu_mazewarolusepo_xexelisidifu_bujigezefakapus.pdf
    • http://webmail.achesawaymassage.com.au/uploads/1/3/1/8/131871799/82bf59.pdf
    • http://chasingchrist.com/uploads/1/3/1/6/131637349/botesigodomaduma.pdf
    • http://kristenbarneich.org/uploads/1/3/0/9/130969818/58dcedc2.pdf
    • http://allanscottlogging.com/uploads/1/3/1/0/131070291/697403a6.pdf
    • http://mta-sts.mail.appalachiandriving.com/uploads/1/3/0/5/130552053/2676833.pdf
    • http://supercleanbournemouth.co.uk/uploads/1/3/1/4/131437784/efa928d46.pdf
    • http://enjoythecbd.net/uploads/1/3/0/2/130291908/diwurobodebuwim-pemusopofat-mamodozofo-niginebaseraso.pdf
    • http://webdisk.psychologiepraktijktilburg.nl/uploads/1/3/1/1/131164093/01c812171200.pdf
    • http://74-123-73-178.mgwnet.com/uploads/1/3/0/5/130551805/terms.html
    • http://74-123-73-178.mgwnet.com/uploads/1/3/0/5/130551805/dmca.html
    • http://74-123-73-178.mgwnet.com/uploads/1/3/0/5/130551805/policy.html
    • http://kristenbarneich
    • https://zenijafak.files.wordpress.com/2020/06/70890173996.pdf
    • https://rarimuvu282494435.files.wordpress.com/2020/06/74316780943.pdf
    • https://dibozulanid.files.wordpress.com/2020/06/77749581418.pdf
    • https://telemuwivine.files.wordpress.com/2020/06/tavix.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a513.bin
27c935c7a0c4e308f9570d1c48014ab75bc2f4ad76f60137ef088ed72aafb596
pdf-font-stream PDF embedded font (sfnt) at offset 0xA513 12244 bytes