Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4ec675f8328699b…

MALICIOUS

PDF

40.9 KB Created: 2020-03-23 11:49:32 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: bc64169368e63fe9065d07b35397e94b SHA-1: 4c6f28c50ebae068bb5e509a3cb8b5c56fde094c SHA-256: c4ec675f8328699ba411c776d7a32d59e752935931bda054d3489f8d3fd052cb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document exhibits characteristics of a link farm, containing numerous external links to other PDF files hosted across various domains. The primary URL points to a page discussing angles in a circle, likely a lure to disguise the malicious intent. The heuristic 'PDF_SEO_LINK_FARM' strongly indicates this is a tactic to generate traffic or distribute further malicious content. No scripts were extracted, and the document body is largely unreadable binary data, but the extensive network of linked PDFs is a clear indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://livrese.net/uploads/1/3/0/5/130588289/130588289.html#que+tipos+de+angulos+hay+en+un+circulo
    • http://mail.starmijan.com/uploads/1/3/0/6/130621533/rowutitedevaledu.pdf
    • http://cellitelectronics.com/uploads/1/3/0/6/130605168/6577493.pdf
    • http://alternativemedicine24.com/uploads/1/3/0/8/130873986/2842464.pdf
    • http://motorheadtv.com/uploads/1/3/0/7/130739480/e274a3dd5145b85.pdf
    • http://www.cricketkustomz.com/uploads/1/3/0/3/130313470/4477249.pdf
    • http://favoritewordsmith.com/uploads/1/3/0/6/130621342/def3dfa6b588c6.pdf
    • http://handmadegrain.com/uploads/1/3/0/9/130969685/7e525b511.pdf
    • http://robinagricola.com/uploads/1/3/0/8/130874413/nurapegujoji.pdf
    • http://acg-amg.com/uploads/1/3/0/8/130874170/cbe2b.pdf
    • http://cleanmellc.com/uploads/1/3/0/2/130289630/2043551.pdf
    • http://jlynnnutrition.com/uploads/1/3/0/2/130270777/jokewog.pdf
    • http://lift4life.com/uploads/1/3/0/4/130436068/werutozuges.pdf
    • http://itoption.dk/uploads/1/3/0/6/130640074/dopivulefugu.pdf
    • http://evelynhsullivanmediation.com/uploads/1/3/0/2/130270953/naminag-zixoj-fipizizu-wixipopazoviw.pdf
    • http://kristina-parker.com/uploads/1/3/0/6/130603913/7503548.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ab0.bin
88989f21749f1ccfac274b0318b7920c1558f39de28ab520507d91eb8fa2d2e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AB0 8392 bytes
font_01_sfnt_off00008942.bin
c048ac4ed90d63bfae46472f65f9cf6fc0bd5e75369f2d8f28771a6d96a2731c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8942 3156 bytes