Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d82b0504730dc38…

MALICIOUS

PDF

40.3 KB Created: 2020-03-21 18:00:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: c40f2c8e340e29244223f4d4c48b587e SHA-1: c5447c314a4465db7544dd1adcba9a46412657c3 SHA-256: 9d82b0504730dc3870a1c49dc4ab7d94a0a64215d6852ddda018d4ac80660368
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links to other PDF files hosted on various domains, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body text, though partially corrupted, includes the phrase 'Resumen del libro se buscan locos', suggesting a lure related to a book. The primary attack pattern involves redirecting users to a vast network of linked PDFs, likely for SEO spam or to distribute further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mindforyou.org/uploads/1/3/0/3/130323889/130323889.html#resumen+del+libro+se+buscan+locos
    • http://dpntransport.com/uploads/1/3/0/7/130776300/voginatotoze.pdf
    • http://www.talk-of-the-town.org/uploads/1/3/0/6/130605285/af89b9a2.pdf
    • http://heritagetreeservice.com/uploads/1/3/0/5/130590432/4eb1872bd09.pdf
    • http://www.thelangsisters.com/uploads/1/3/0/6/130639246/dagiguvu_tefuso_jabin.pdf
    • http://cypresspointerehabhc.com/uploads/1/3/0/2/130287862/7685447.pdf
    • http://raesham.com/uploads/1/3/0/2/130287482/giwaj_dotixopanar_fusamaterev_kafinifodu.pdf
    • http://coreview.us/uploads/1/3/0/3/130324050/7dceffd03e.pdf
    • http://reviewscover2cover.com/uploads/1/3/0/5/130588384/bajisose.pdf
    • http://brokecube.com/uploads/1/3/0/8/130814460/4691700.pdf
    • http://www.gclbd.org/uploads/1/3/0/6/130603798/bidutuzobur.pdf
    • http://miamirehearsal.com/uploads/1/3/0/7/130776605/xupozigapabo.pdf
    • http://morsecodedesigns.com/uploads/1/3/0/7/130739007/74063.pdf
    • http://nikolasstrubbe.com/uploads/1/3/0/6/130604933/5132953a9.pdf
    • http://fritzwrites.com/uploads/1/3/0/2/130291589/zajuluxojod.pdf
    • http://sharepreview.com/uploads/1/3/0/4/130483820/7702101.pdf
    • http://wholesomevitamins.com/uploads/1/3/0/2/130272394/nisafijujusep-jimidukarogaso.pdf
    • http://ownedbrands.net/uploads/1/3/0/7/130775429/4ab47177b6d6.pdf
    • http://foxongardens.com/uploads/1/3/0/2/130291029/vopur.pdf
    • http://clicktexttiles.com/uploads/1/3/0/5/130588352/4356585.pdf
    • http://www.janeturner.org.uk/uploads/1/3/0/5/130543333/6359693.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000736b.bin
6beaa93577c31c10a0f080bd6b6bf70a0ec6a3e07df0cad08269dc87ba9e8e30
pdf-font-stream PDF embedded font (sfnt) at offset 0x736B 8572 bytes