Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3f4700e3151ade6…

MALICIOUS

PDF

90.8 KB Created: 2020-04-29 13:29:46 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 019f77b71b5c414845e47b700407ac6a SHA-1: 50976d556ab6d3d9445050cbfaa625b5f75a27ec SHA-256: a3f4700e3151ade6f7dafb446e5c541db213f8d08a275a800d08a3099acc9933
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to other PDF files hosted on various domains. This behavior is indicative of a link farm or a mechanism to distribute malicious content through a network of compromised or controlled websites. The document body, though heavily obfuscated, contains a URL that appears to be part of this link farm. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://shanalathrop.com/uploads/1/3/0/9/130969356/130969356.html#diabetes+nice+guidelines+pregnancy
    • http://farmboyconsulting.com/uploads/1/3/0/3/130323417/b6406213c9.pdf
    • http://patriotpreciousmetals.com/uploads/1/3/0/2/130289282/9fccfee4c0f.pdf
    • http://theskinnyresources.com/uploads/1/3/0/6/130605108/5b9031446.pdf
    • http://aferminprimarycare.com/uploads/1/3/0/2/130287914/d15f395e2262.pdf
    • http://masterbarberrr.com/uploads/1/3/0/9/130969840/pebaxefamoradi.pdf
    • http://duncanskatingclub.net/uploads/1/3/0/2/130270895/b310ac8042af23.pdf
    • http://blackwomensyogaretreats.com/uploads/1/3/0/7/130776452/depogotapudim.pdf
    • http://mandatorybusiness.com/uploads/1/3/0/2/130289703/6f808e26d9ec7.pdf
    • http://boutique2door.com/uploads/1/3/1/3/131383726/pefizakilobi-moromogalonev-jolepewamesu-tejujiseb.pdf
    • http://marisstellakg.org/uploads/1/3/0/6/130620142/8570357.pdf
    • http://dcconcept.org/uploads/1/3/0/7/130740209/1049937.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012873.bin
2fbe200edf7ddcb32cf1c504ae85a1c0b2048e13fb170fa412b3cdd070d1058d
pdf-font-stream PDF embedded font (sfnt) at offset 0x12873 8108 bytes
font_01_sfnt_off000147e0.bin
ddc6c38a5929b263b215a5b0c7aa8b1a409f146866f06980111f9f21a6232bf4
pdf-font-stream PDF embedded font (sfnt) at offset 0x147E0 16036 bytes