Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba22d8f4573de1a6…

MALICIOUS

PDF

87.6 KB Created: 2020-04-02 03:18:28 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a753045398f488d654971bcccb1c8c58 SHA-1: b9bb73087fc59fbcbd731ba8a5ef4eec79e04194 SHA-256: ba22d8f4573de1a65c273ff0d7f078e7ca532bd31e2265b934e55b61aad6bc9d
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which point to other PDF files hosted on similar domains. This behavior is indicative of a link farm or SEO manipulation tactic, often used to distribute malicious content or engage in phishing. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://andersonmotorcycleattorney.com/uploads/1/3/1/0/131070072/131070072.html#hitler%27s+paintings+worth
    • http://monaco-trade.com/uploads/1/3/0/6/130603779/6501141.pdf
    • http://myfujingarts.com/uploads/1/3/0/6/130603969/sapuvipuwoxebobag.pdf
    • http://osborgoflove.com/uploads/1/3/1/3/131379227/3294833.pdf
    • http://comfy-blankets.com/uploads/1/3/0/5/130548152/xubojaninan.pdf
    • http://georgeratkevich.com/uploads/1/3/0/2/130272482/6745441.pdf
    • http://aph1.aphorticultura.pt/uploads/1/3/0/5/130539922/6523793.pdf
    • http://nightowlsoulclubs.com/uploads/1/3/1/4/131438405/abf2f1e3bdd.pdf
    • http://debbiecopeland.net/uploads/1/3/0/6/130639848/tarojatidu.pdf
    • http://www.bullwarkscreens.com/uploads/1/3/0/4/130489162/fb914e019015b0b.pdf
    • http://abbymenagerie.com/uploads/1/3/1/4/131453062/kisof.pdf
    • http://platinumflights.com/uploads/1/3/0/8/130874035/lisilikun.pdf
    • http://1833gayosa.com/uploads/1/3/0/3/130379231/miwuj.pdf
    • http://mimmyskitchen.com/uploads/1/3/0/2/130273812/xokujitijo_niwemumorema.pdf
    • http://jewelrystoresinnh.com/uploads/1/3/0/9/130969245/3e067.pdf
    • http://massicredit.com/uploads/1/3/0/3/130379305/7b1f56ec723cc7.pdf
    • http://myfinancialadvise.com/uploads/1/3/0/2/130289738/317c6.pdf
    • http://christianenergywork.com/uploads/1/3/0/5/130548070/56ad5f049169f.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000127cd.bin
626c160019eba47ad28deaad65fb09ec64f01a09288b47a02ca53ffc637f795d
pdf-font-stream PDF embedded font (sfnt) at offset 0x127CD 13152 bytes