Malicious PDF — malware analysis report

Static analysis result for SHA-256 9edb191936bbf44c…

MALICIOUS

PDF

48.0 KB Created: 2020-04-09 03:41:25 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9e1e00c85a208493a3d78a5276d62d5f SHA-1: f7837aa3ba1f1e8dcaaceabeab07d3e38222af08 SHA-256: 9edb191936bbf44c7c3480873707bca6d90f470502812bda01624a852fe8d17c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1598 Gather Information T1598.003 Subdomain Acquisition

The PDF contains a large number of external links, many of which point to other PDF files hosted on various domains. This pattern is indicative of a link farm or SEO spamming technique, potentially used to distribute malicious content or improve search engine rankings for undesirable sites. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://stopeurocide.com/uploads/1/3/1/4/131409861/131409861.html#cancer+horoscope+today+ask+ganesha
    • http://popsup.org/uploads/1/3/0/9/130969798/lebedivig.pdf
    • http://gingabreadhouse.com/uploads/1/3/0/2/130289774/zovotuwimisam.pdf
    • http://musicanddancecolumbia.net/uploads/1/3/0/7/130775719/6927a0bc6df.pdf
    • http://1misophonian.com/uploads/1/3/0/6/130620460/soxuxifev-tebunadud-luwanifobi.pdf
    • http://partitimedoods.com/uploads/1/3/1/3/131398324/7462213.pdf
    • http://serviziaeroportualisas.it/uploads/1/3/0/4/130436415/852448.pdf
    • http://nsefitness.com/uploads/1/3/0/7/130776864/4615942.pdf
    • http://sh-equestrian.com/uploads/1/3/0/7/130740427/bedowet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009210.bin
4688afb356e752752de660fab83ee26157ebe82558a63fdc016c7048447a19cd
pdf-font-stream PDF embedded font (sfnt) at offset 0x9210 8232 bytes