Malicious PDF — malware analysis report

Static analysis result for SHA-256 d414a137a8005f94…

MALICIOUS

PDF

38.8 KB Created: 2020-06-03 14:39:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: acc5f2a8d2ff1ffeb78c7b8acbb0a170 SHA-1: d00dad5d131b8d113e2f26b577640e04f85cd53b SHA-256: d414a137a8005f9402df3f70372d9fc46306c02e74e2b3f847dd6260c441b036
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on different domains. The document body text, though partially obfuscated, includes the phrase 'Aceptacion incondicional pdf' and repeats several of the external URLs. This suggests a link farm or SEO manipulation tactic, potentially used to distribute malicious content or drive traffic to attacker-controlled sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mx.imaniyako.org/uploads/1/3/0/2/130287923/130287923.html#aceptacion+incondicional+pdf
    • http://cpanel.mrclarkspe.com/uploads/1/3/1/3/131378796/nebuwobulilixeg.pdf
    • http://tacoselcuate.com/uploads/1/3/0/3/130313422/vesasudedeba.pdf
    • http://schgoc.com/uploads/1/3/0/3/130313671/pimefiripika.pdf
    • http://4bodyandsole.com/uploads/1/3/0/7/130738676/20b593.pdf
    • http://mx.desire4pleasure.com/uploads/1/3/0/7/130738705/9940881.pdf
    • http://invite-change.com/uploads/1/3/1/6/131637307/puburisebotemimaz.pdf
    • http://summit2019houston.com/uploads/1/3/1/3/131398543/8243780.pdf
    • http://charitytothestreet.com/uploads/1/3/0/2/130289369/wubojomuku.pdf
    • http://sm-pipe.com/uploads/1/3/1/4/131406879/menalomelulupironu.pdf
    • http://mta-sts.mx.a1windshield-vinylrepair.com/uploads/1/3/0/7/130776015/5360444.pdf
    • http://webmail.hermitagefbc.com/uploads/1/3/0/6/130621455/f8029d60c.pdf
    • http://mta-sts.mx.clintonpottery.com/uploads/1/3/1/4/131453871/5912220.pdf
    • http://mx.imaniyako.org/uploads/1/3/0/2/130287923/terms.html
    • http://mx.imaniyako.org/uploads/1/3/0/2/130287923/dmca.html
    • http://mx.imaniyako.org/uploads/1/3/0/2/130287923/policy.html
    • https://zisagan.files.wordpress.com/2020/05/sitiz.pdf
    • https://jumitedav.files.wordpress.com/2020/05/42053625456.pdf
    • https://tujirunovu.files.wordpress.com/2020/05/dejivuzetafikodetale.pdf
    • https://bivuwid.files.wordpress.com/2020/05/81898141075.pdf
    • https://defamufomowa.files.wordpress.com/2020/05/17526792818.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006be2.bin
374395b6e80ad57149ce4ead022c0160b47280a0a379a98cf7b21dfee5d5d0ae
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BE2 11492 bytes