Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0b02e69b9012b5e…

MALICIOUS

PDF

37.6 KB Created: 2020-04-05 05:57:02 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9d8ffc7b6f0c272e9f008c94de5a1974 SHA-1: 89db46a5c9c57c63e58184e72bd1a88ff0580fcc SHA-256: a0b02e69b9012b5ed9d77fedc57bddf6f72e2aab81b2a8b9104719fe98da0e59
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The document body contains the text 'Utileria teatral venta', which appears to be a lure. The primary intent seems to be directing users to a network of potentially malicious or SEO-abused websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://myclassicmercedes.com/uploads/1/3/0/6/130620321/130620321.html#utileria+teatral+venta
    • http://matthewcicciophotography.com/uploads/1/3/0/2/130289760/4344445.pdf
    • http://qualitycarediagnostics.com/uploads/1/3/0/6/130604473/tefobasufesitevowez.pdf
    • http://perirgo.org/uploads/1/3/0/2/130289585/sogalefivilafasopa.pdf
    • http://azlanadnan.com/uploads/1/3/0/6/130620885/4537021.pdf
    • http://spoiledatfirstdrop.com/uploads/1/3/1/3/131379543/9220747.pdf
    • http://klikstarter.com/uploads/1/3/0/6/130621321/5965758.pdf
    • http://mitleichtigkeitmamasein.com/uploads/1/3/0/5/130589121/c76a0.pdf
    • http://themotivist.com/uploads/1/3/1/3/131380564/7959674.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006753.bin
e468c22bc6a12b1d52baf58fc6260b2691fb66ae1a24c775095c5bf20e8d8259
pdf-font-stream PDF embedded font (sfnt) at offset 0x6753 9160 bytes