Malicious PDF — malware analysis report

Static analysis result for SHA-256 bec48d854018e37f…

MALICIOUS

PDF

60.8 KB Created: 2020-03-31 00:53:04 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: bb69c93a166eb74a22bd363e5f1c597a SHA-1: b41803d2c3457347f05902d5faabf9609db3340a SHA-256: bec48d854018e37fc35cae63a798e486e1491fafff35539ccdd38b524f94f1cf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a lure related to installing a car seat, but its primary function is to act as a link farm. It directs users to numerous external PDF files hosted on various domains, indicating a campaign to artificially inflate traffic or distribute further malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wolfecityhomecoming.com/uploads/1/3/0/5/130539516/130539516.html#installing+front+facing+evenflo+car+seat
    • http://healthyeatingandliving.org/uploads/1/3/0/4/130488626/9190420.pdf
    • http://andreandgretchen.com/uploads/1/3/0/8/130874221/bojemowe.pdf
    • http://claytonheightssportmassage.com/uploads/1/3/0/7/130775830/ligebigizose.pdf
    • http://riotable.com/uploads/1/3/0/3/130312961/rinim.pdf
    • http://aussiewoodfilms.com/uploads/1/3/0/6/130640119/75c62d.pdf
    • http://winterwide.com/uploads/1/3/0/2/130274370/5597662.pdf
    • http://mentzerlawgroup.com/uploads/1/3/0/6/130621119/kazukesadiwudiw-popuporev-visunoxi.pdf
    • http://freshcoastfloral.com/uploads/1/3/0/5/130590548/webukob.pdf
    • http://mammaas.nl/uploads/1/3/0/6/130639743/8496369.pdf
    • http://malikarosetennis.com/uploads/1/3/0/6/130604742/a0b201d6d85ebf7.pdf
    • http://loveandlightbeyours.com/uploads/1/3/0/9/130969368/41c6cb8.pdf
    • http://bigsuperman.com/uploads/1/3/0/4/130475892/e33eb0.pdf
    • http://rn-performance.com/uploads/1/3/0/5/130550992/7255571.pdf
    • http://informationsuperglacier.net/uploads/1/3/0/2/130291463/3223575.pdf
    • http://phoenixvisiontech.ca/uploads/1/3/0/7/130739197/fuwigawudekodosabidi.pdf
    • http://kreuzbach10.com/uploads/1/3/0/9/130969000/dopeniva.pdf
    • http://overcoming-ptsd.info/uploads/1/3/1/3/131384694/402756.pdf
    • http://fishfindersaustralia.com.au/uploads/1/3/0/4/130489499/jijupewi_lasolalezororad_ranuwa_jomotavasi.pdf
    • http://www.superscoreme.com/uploads/1/3/1/0/131070651/9848250.pdf
    • http://3dsaps.com/uploads/1/3/0/5/130539107/dekufagamom-sozizel.pdf
    • http://www.cdbconfeccoes.com/uploads/1/3/0/7/130739590/c2d04cec16cee3.pdf
    • http://mycleanohio.com/uploads/1/3/0/5/130544547/8847839.pdf
    • http://cambridgeblackcar.com/uploads/1/3/0/2/130289371/4350340.pdf
    • http://cassandraneuhauspsyd.com/uploads/1/3/0/5/130543453/c7cdc.pdf
    • http://divimar.com/uploads/1/3/1/1/131164252/8a7263a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b87f.bin
8e080b2649a12661db012742f488884b6a8efcc3b9c621cd3bd44e3649319410
pdf-font-stream PDF embedded font (sfnt) at offset 0xB87F 8504 bytes
font_01_sfnt_off0000d921.bin
d907c570f1f8f2d62f38d7529dbf77de46ca3a1917ec53aca7a78bae59874b04
pdf-font-stream PDF embedded font (sfnt) at offset 0xD921 2616 bytes