Malicious PDF — malware analysis report

Static analysis result for SHA-256 c39d34427778a001…

MALICIOUS

PDF

37.5 KB Created: 2020-03-22 08:48:05 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a60fbf10e2b2713f0838eaf71823ec0e SHA-1: 84d15563432cb831d51fabdfb3a8d04dacce02b5 SHA-256: c39d34427778a0013120f40e0d0a23e039840791098087754e04816161880383
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links to other PDF files hosted on various domains. This pattern is indicative of SEO spam or a link farm designed to distribute malicious content or manipulate search engine rankings. The ML classifier strongly supports the malicious nature of this PDF. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://yourchairmansclub.us/uploads/1/3/0/4/130483679/130483679.html#conversione+da+pascal+ad+atmosfere
    • http://palazzo-estates.com/uploads/1/3/0/6/130639699/giluje.pdf
    • http://youuoyrecords.org/uploads/1/3/0/5/130542769/dawiburotafupuxuwa.pdf
    • http://hostmaster.beachkick.com/uploads/1/3/0/5/130589171/kaxidawixagef.pdf
    • http://www.yourpracticemultiplier.net/uploads/1/3/0/4/130488812/kined-faxenojobive-zegivotodevavem.pdf
    • http://smallbusinesswebdesign.company/uploads/1/3/0/7/130775782/1127394.pdf
    • http://franksecen.com/uploads/1/3/0/9/130969343/139428fe7b73b.pdf
    • http://www.yabadi.org/uploads/1/3/0/8/130814219/merewibajiba-kaboki-tonugunomiz-jovakebasezi.pdf
    • http://foodabouttown.net/uploads/1/3/0/5/130588899/kajafa.pdf
    • http://matsohaholdings.net/uploads/1/3/0/7/130739816/4336596.pdf
    • http://abitoflace.com/uploads/1/3/0/5/130588618/fefuxox_metoxijejuf.pdf
    • http://www.pillarsofart.com/uploads/1/3/0/7/130775840/d713480d446.pdf
    • http://iaminclusive.com/uploads/1/3/0/8/130813483/komusonijeke.pdf
    • http://www.nayaraduran.com/uploads/1/3/0/3/130313199/cce93b6.pdf
    • http://neighborhoodinvolve.org/uploads/1/3/0/7/130775504/3871079.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006815.bin
ae5b554d4c9eaf47c00f2e83ed0b6e34dc3068d1381723cd7751defd53a81cd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6815 8440 bytes