Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7cdf78b4a40e13b…

MALICIOUS

PDF

52.9 KB Created: 2020-03-30 13:07:34 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a2e2b6f2e5df47dbacfb2d8b34b18ae4 SHA-1: 11bdf39f094c8c075b30822d63747df2256a0b1c SHA-256: c7cdf78b4a40e13bb7ce97b14397ff8f4ffd0c684d7b0cf28f0eb24343bfef6e
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to other PDF files, masquerading as educational resources. The primary URL, http://bsa-sccc-pack301.com/uploads/1/3/0/7/130740196/130740196.html#gramatica+basica+del+estudiante+de+espa%C3%B1ol+difusion+pdf, is presented as a Spanish grammar book but likely serves as a lure. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links generated for SEO purposes, suggesting a link farm or redirection scheme to distribute malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bsa-sccc-pack301.com/uploads/1/3/0/7/130740196/130740196.html#gramatica+basica+del+estudiante+de+espa%C3%B1ol+difusion+pdf
    • http://businessattorneyguide.com/uploads/1/3/0/8/130874067/3047722.pdf
    • http://metropolitaneprep.com/uploads/1/3/0/8/130814508/pavunijedosi.pdf
    • http://bim-plicity.com/uploads/1/3/1/0/131070284/0d5476c039ba1.pdf
    • http://laurenshaw.org/uploads/1/3/1/4/131408353/dupemiweworimoxi.pdf
    • http://whynotourcity.com/uploads/1/3/0/8/130814209/gufijidagamux.pdf
    • http://twohorsefarms.com/uploads/1/3/0/6/130639599/kuxapetonuxijume.pdf
    • http://yourlistener.ca/uploads/1/3/0/7/130776212/8026096.pdf
    • http://noccassoc.org/uploads/1/3/1/1/131164118/jiloto.pdf
    • http://larson-homes.com/uploads/1/3/0/9/130969663/d23e42db06e3.pdf
    • http://livegenics.com/uploads/1/3/1/1/131164011/0b9a05c03.pdf
    • http://erisports.net/uploads/1/3/1/3/131378821/34b798e7.pdf
    • http://1169certified.org/uploads/1/3/1/3/131384142/rudezowemesogoz_titumurizon_vipozagiwu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009f8e.bin
7099c8d0d161e8066b731a2dfb0970b598c85e3a0014ec0a4e9ed950ed5b0528
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F8E 10748 bytes