Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd24170bdfb114fd…

MALICIOUS

PDF

48.4 KB Created: 2020-03-13 05:19:31 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ba0fb06901052e3fb2f22d998b5a246d SHA-1: 57087e05f7c5e49bf3946ca476dec58a95affb5c SHA-256: cd24170bdfb114fd1d90d77f5debecb117f37f775347f4ab9c8968e5178a819b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous external links, many of which are hosted on domains designed for SEO manipulation, indicating a link farm strategy. The primary external URI points to a page with a deceptive title, suggesting a lure to a malicious website. The ML classifier strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vps14-internal.pleasingfood.com/uploads/1/3/0/5/130590200/130590200.html#balanced+chemical+equation+of+propanol+++ethanoic+acid
    • http://bergeronchryslercomplaints.com/uploads/1/3/0/5/130590677/jubufusavoxokemok.pdf
    • http://brochuaccounting.com/uploads/1/3/0/6/130621608/6fab30.pdf
    • http://www.blueribbonbreeder.com/uploads/1/3/0/9/130969506/mobavotovidisakisofu.pdf
    • http://brazilianblowoutchinohills.com/uploads/1/3/0/7/130775167/xakotuxok_sodikumifuke.pdf
    • http://www.chaddock-family.rominastiebenphotography.com/uploads/1/3/1/0/131070207/36f8436e83.pdf
    • http://thefishingday.com/uploads/1/3/0/4/130483631/7679716.pdf
    • http://autodiscover.southplatteforum.org/uploads/1/3/0/7/130738835/6918773.pdf
    • http://injuryattorneyfortworth.com/uploads/1/3/0/2/130291822/giwibexunek.pdf
    • http://chasehouser.com/uploads/1/3/0/7/130776714/sosaniw.pdf
    • http://whatswearing.com/uploads/1/3/0/7/130740504/742e12.pdf
    • http://1169training.com/uploads/1/3/0/6/130621357/bazekereteruf.pdf
    • http://www.newfoundseeds.com/uploads/1/3/0/3/130324350/cf88c4432058e.pdf
    • http://onlinefitnessunderground.com/uploads/1/3/0/7/130776718/viwitodoloxad-meretalodime-lavage-livexolatabaje.pdf
    • http://standstrongcoalition.com/uploads/1/3/0/7/130775592/9103059.pdf
    • http://realizingmedia.net/uploads/1/3/0/6/130640194/5e75c.pdf
    • http://nadiaprice.com/uploads/1/3/0/8/130874121/vujisigar-magusa.pdf
    • http://quangcaochietkhau.com/uploads/1/3/0/7/130775127/nesenirodonebitinato.pdf
    • http://misslindsaywillson.com/uploads/1/3/0/4/130489564/8088244.pdf
    • http://mindbodyevolution.org/uploads/1/3/0/5/130590351/4600570.pdf
    • http://nevadalawguide.com/uploads/1/3/0/5/130589354/nopakena.pdf
    • http://parroccasangejtanu.com/uploads/1/3/0/4/130435794/3500d.pdf
    • http://auzmoki.com/uploads/1/3/0/2/130291033/402d08ea01d778.pdf
    • http://site.justinboyer.com/uploads/1/3/0/3/130323412/9877954.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008a0b.bin
3ae02d9782425f3e39412ba0a91cbeee7ce2b50e9389cf4721eeafd11e23ff6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A0B 8712 bytes
font_01_sfnt_off0000ab49.bin
e2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea
pdf-font-stream PDF embedded font (sfnt) at offset 0xAB49 2652 bytes