Malicious PDF — malware analysis report

Static analysis result for SHA-256 a070cdf11e4f1820…

MALICIOUS

PDF

56.3 KB Created: 2020-04-02 01:48:56 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: af940c744ff882fb92c9de7faccd8444 SHA-1: ab3fb3ae6166a27ce6e1b9635181dc2991284b82 SHA-256: a070cdf11e4f1820941115cdfb47f2f5ce4984de04ed93cf75d7369b8923273d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF document is designed as a lure, using a "how-to" topic to entice users to click on embedded links. The PDF_SEO_LINK_FARM heuristic indicates that the document contains a large number of external links, likely for SEO manipulation or to distribute further malicious content. The ML classifier strongly supports the malicious nature of this PDF. The primary attack vector appears to be directing users to a network of linked PDFs hosted on various domains.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://phoying.net/uploads/1/3/0/4/130476766/130476766.html#how+to+connect+a+canon+pixma+mx410+printer+to+wifi
    • http://jamesmilliken.com/uploads/1/3/0/6/130621194/kizujanovokubinanir.pdf
    • http://simplicityyoursevents.com/uploads/1/3/0/6/130604616/xuzen_wasipekibagiz.pdf
    • http://mx.angelindy.com/uploads/1/3/0/7/130776040/039b16.pdf
    • http://bluebirddollshoppe.com/uploads/1/3/0/2/130272482/1155624.pdf
    • http://experiencevintagehome.com/uploads/1/3/0/2/130272260/70bbc5c2069f9d6.pdf
    • http://statordrone.com/uploads/1/3/1/3/131381151/kixidenasaxetunaron.pdf
    • http://limitlessvoyage.com/uploads/1/3/0/5/130590371/tasasivupibak.pdf
    • http://bobdaviswrites.com/uploads/1/3/0/7/130776185/6078584.pdf
    • http://hairbyciera.com/uploads/1/3/0/6/130639790/gutakexu_jisolodixapexe_bubesatuse_bozuzonujan.pdf
    • http://thelifeiwantgroup.com/uploads/1/3/0/7/130740502/werixalukivu-lawub-zanufa.pdf
    • http://rockonjames.com/uploads/1/3/0/7/130776025/27c03396ba9.pdf
    • http://apmount.com/uploads/1/3/0/2/130287988/99f318e90.pdf
    • http://lpcoalition.com/uploads/1/3/0/6/130621005/nopiw.pdf
    • http://eastbournewindowcleaning.com/uploads/1/3/1/0/131071278/bezarav.pdf
    • http://akdlegal.com/uploads/1/3/0/7/130775025/gomumeb.pdf
    • http://theworldnearby.shop/uploads/1/3/1/4/131438888/kixuxaxizaroto-kanibela-kurobiwusu-wevuxowiwe.pdf
    • http://patrickjmcgarrity.com/uploads/1/3/0/8/130873976/wilufilumilex-mikejigiju.pdf
    • http://recycledtimberfurnituremelbourne.com/uploads/1/3/0/6/130621218/teveni.pdf
    • http://bodiibyjayy.com/uploads/1/3/0/5/130539016/vegimokizekesuzil.pdf
    • http://sugarbombshop.com/uploads/1/3/0/6/130604081/9812509.pdf
    • http://atlantamotionpicturesstudios.com/uploads/1/3/0/5/130589095/3c71a413df1.pdf
    • http://sophianesamoney.com/uploads/1/3/0/4/130476940/8570632.pdf
    • http://pcrp.info/uploads/1/3/0/6/130621458/c83438.pdf
    • http://4curlz.com/uploads/1/3/0/4/130488295/ranapodezubirepiwaxi.pdf
    • http://nabj.uga.edu/uploads/1/3/0/9/130969776/542254.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b20f.bin
fecf2604ac2580013e1de2b246eec956ab2c8c934c102a4a5170e673a5c0d7af
pdf-font-stream PDF embedded font (sfnt) at offset 0xB20F 8460 bytes