Malicious PDF — malware analysis report

Static analysis result for SHA-256 af294f001539d896…

MALICIOUS

PDF

38.0 KB Created: 2020-03-30 11:43:59 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: bcb505f2a1d40a865b923da99b73a675 SHA-1: ccd71be654f11c5183092fe29bdbfda3aafb1b14 SHA-256: af294f001539d8966f201127586599c6b517ba97afff5c7ce87b3dcf89f99bfb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was identified as malicious by an ML classifier. It contains a large number of external links, indicating it functions as a link farm. The primary purpose appears to be SEO manipulation or distributing further malicious content through the numerous linked PDFs. The document body contains the title 'Palabras que comienzan con zar' and references wkhtmltopdf, suggesting it was generated programmatically.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bejustalittlebetter.com/uploads/1/3/0/4/130475928/130475928.html#palabras+que+comienzan+con+zar
    • http://towerviewsuites.com/uploads/1/3/0/6/130621459/0617103df.pdf
    • http://purevoyage.net/uploads/1/3/0/5/130590569/a7d169df93.pdf
    • http://crossfadeservices.com/uploads/1/3/0/6/130604494/sepelu-mibus-vuzubif.pdf
    • http://cancun-tickets.com/uploads/1/3/0/6/130605065/bowanezotojot-nizeragezexudux.pdf
    • http://123chinese.org/uploads/1/3/0/6/130639770/dajok.pdf
    • http://openradio.es/uploads/1/3/1/3/131382078/eda81265a7.pdf
    • http://millteacher.com/uploads/1/3/0/2/130291971/jorobisafobavig_furofito_rexis_vonusisimelij.pdf
    • http://hardwoodflooringstlouis.com/uploads/1/3/0/6/130605173/7912138.pdf
    • http://thearmory.io/uploads/1/3/0/5/130544468/a9fbe1a87da71.pdf
    • http://veridicalfinance.com/uploads/1/3/0/7/130740617/dovajinefafexaz.pdf
    • http://armwrestlinghistory.com/uploads/1/3/0/8/130874031/tijojiponizadotugop.pdf
    • http://southbayluaus.com/uploads/1/3/0/6/130639147/9345025.pdf
    • http://mydarlingvalentine.com/uploads/1/3/0/7/130775383/zamevuf_gorax_kupowazaw_tifitodabotonat.pdf
    • http://usafacpc.afaparents.org/uploads/1/3/0/8/130814421/1002698.pdf
    • http://2drygear.com/uploads/1/3/0/7/130776130/fanovenuvekimavederi.pdf
    • http://feedtheneedy.net/uploads/1/3/0/5/130539843/jazizaka.pdf
    • http://alhosani.net/uploads/1/3/1/3/131380870/ed900e7f8e.pdf
    • http://barbaramedford.com/uploads/1/3/0/6/130604499/lubozijit-xudamibu-rexepiro-kivopugug.pdf
    • http://westsaclibfriends.org/uploads/1/3/0/6/130604798/7148184.pdf
    • http://mail.wapitinordic.com/uploads/1/3/0/6/130620788/poxexebavajitewe.pdf
    • http://gigbags.cn/uploads/1/3/0/6/130620441/3672589.pdf
    • http://lifemotivationmarketing.com/uploads/1/3/0/4/130490928/2176112.pdf
    • http://norwichmonument.com/uploads/1/3/0/5/130551000/zopujivelaxid.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069cf.bin
df49523bca5b9f876013ad332a3bf5fd96a968514d2d9afca9850d709b539cab
pdf-font-stream PDF embedded font (sfnt) at offset 0x69CF 8500 bytes