Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac74f2f27f521d20…

MALICIOUS

PDF

41.5 KB Created: 2020-03-28 05:54:10 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a76925c71c04d1d9ce51b3e59c27c0c7 SHA-1: bd35eb0f1597feb6bff90878e60ceb591c3d4baf SHA-256: ac74f2f27f521d205dd8c9324b11c753ca98d1e4ab736caa475f12216dfb7844
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, many pointing to other PDF files, suggesting a link farm or redirection mechanism. The document body, though partially corrupted, indicates it is presented as educational material for children. The ML classifier strongly flagged this PDF as malicious. The primary intent appears to be directing users to a network of suspicious URLs, likely for further exploitation or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://deceptivelysimple.com/uploads/1/3/1/3/131379231/131379231.html#practicas+de+comprension+de+lectura+para+ni%C3%B1os+de+segundo+grado
    • http://ncbeertours.com/uploads/1/3/0/8/130874050/ab48cdc27.pdf
    • http://host94.carmichaelnl.com/uploads/1/3/0/5/130588499/5980333.pdf
    • http://remodel3d.davidmichaeldesigns.com/uploads/1/3/0/3/130379509/wilafodubejew.pdf
    • http://doodlebugblessingsgoldendoodles.com/uploads/1/3/0/8/130813860/b0d01cc8dea2ae4.pdf
    • http://expatsaroundphuket.net/uploads/1/3/0/7/130776822/f6687.pdf
    • http://kesharper.com/uploads/1/3/0/6/130620613/9621442.pdf
    • http://ontimemedicaldevices.com/uploads/1/3/0/4/130435624/ddb540a60934e7.pdf
    • http://polsonoutdoorrentals.com/uploads/1/3/0/4/130483961/554723d48.pdf
    • http://palmetto-technologies.com/uploads/1/3/0/8/130874600/melonoxedofur.pdf
    • http://officehelpsxoy.com/uploads/1/3/0/9/130969462/9560041.pdf
    • http://doctorliliana.com/uploads/1/3/0/6/130603955/gozufinejaxos_movadukad_vorureke_kezebejon.pdf
    • http://midsouthwholesale.net/uploads/1/3/0/6/130603767/1222913.pdf
    • http://robotes.info/uploads/1/3/0/2/130274199/gixadavadunud.pdf
    • http://icounsellinguk.com/uploads/1/3/0/7/130775443/retalu-gepinozizomel-nagimapekatur-sogomepejema.pdf
    • http://74-123-77-209.mgwnet.com/uploads/1/3/0/6/130604896/6553832.pdf
    • http://panavegastudios.com/uploads/1/3/0/6/130620607/xuzepiw.pdf
    • http://www.stacyeye.com/uploads/1/3/0/2/130287462/punasew.pdf
    • http://mta-sts.info.geofernandez.com/uploads/1/3/0/4/130483863/7966735.pdf
    • http://excellrc.com/uploads/1/3/0/2/130291702/256012.pdf
    • http://justinchang.org/uploads/1/3/0/7/130776676/taderaw-lemivazoz-jiwodetara.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007679.bin
6314168c0a12c5162f073501656ea467efaff2e30cf7bb4053e3767685eed402
pdf-font-stream PDF embedded font (sfnt) at offset 0x7679 8448 bytes