Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8e1e191112ecf0c…

MALICIOUS

PDF

35.3 KB Created: 2020-05-15 23:20:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a587d32037d69096379dcfc2284c76a6 SHA-1: aaf67f9173421b274765dfe7071f4416479adaa8 SHA-256: d8e1e191112ecf0c0e3e149949acc0e61cc29491a578d385b8f272782eb9593a
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing:Spearphishing Attachment T1204.002 Malicious File:Malicious Link

The PDF contains a large number of external links, a technique commonly used for SEO poisoning or to distribute malware. The heuristic 'PDF_SEO_LINK_FARM' specifically indicates a mass of external PDF links, with 'dotaciones.net' being a dominant host. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the extensive link farm suggests the primary goal is to redirect users to potentially harmful content hosted on numerous domains.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://havencoachingconsulting.com/uploads/1/3/1/3/131398222/131398222.html#interpave+permeable+pavements+guide
    • http://dotaciones.net/uploads/1/3/1/0/131070168/keliraf.pdf
    • http://shopstrangilrz.com/uploads/1/3/1/4/131407445/1891155.pdf
    • http://creer111.com/uploads/1/3/1/4/131437583/6ed0431d7c65e.pdf
    • http://chippewabowl.net/uploads/1/3/0/7/130739462/jobasubusorel-mofelirifijape.pdf
    • http://hairstylesbystacia.com/uploads/1/3/0/6/130639691/eba37a95e.pdf
    • http://floorfitni.com/uploads/1/3/0/6/130621072/davuser.pdf
    • http://tourbility.com/uploads/1/3/0/5/130551967/2ba02ee97544.pdf
    • http://viewswithrooms.com/uploads/1/3/0/5/130542736/8cfbdeb3e3fa56.pdf
    • http://dacunhalaw.com/uploads/1/3/0/8/130874201/8951165.pdf
    • http://roanokeaa.com/uploads/1/3/0/7/130775808/7236ec2e.pdf
    • http://saramillett.com/uploads/1/3/0/7/130776811/818139.pdf
    • http://daikin-group.it/uploads/1/3/1/1/131164046/3663311.pdf
    • http://twiceisnicetn.com/uploads/1/3/1/0/131069859/9bf2a784ca5b75.pdf
    • http://lan-bar.com/uploads/1/3/0/5/130539849/fodepe-legokafuwovuk-renixizogo-sukokopogeb.pdf
    • http://detransitionstudy.org/uploads/1/3/1/8/131856317/xugepoxulam.pdf
    • http://mysticnavigator.com/uploads/1/3/1/3/131384185/5271646.pdf
    • http://onewaylandscaping.net/uploads/1/3/0/5/130539676/e64b5dbe1a49e9.pdf
    • http://stephenharrisonweb.com/uploads/1/3/0/4/130490221/c2c79.pdf
    • http://redlaceindustries.com/uploads/1/3/1/6/131637780/4137798.pdf
    • http://alefrawedding.com/uploads/1/3/0/4/130483114/4694696.pdf
    • http://bodywiseradio.com/uploads/1/3/0/5/130538816/menete-jopejifakofo.pdf
    • http://rowlandlawtx.com/uploads/1/3/0/7/130740589/wezorew.pdf
    • http://thejob-blog.com/uploads/1/3/0/2/130289658/suvexefitezisiluf.pdf
    • http://biocharreclamation.com/uploads/1/3/0/4/130475981/0afc8e02ded2b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000601f.bin
14400e41e784af28e340d069201a7fbc6f613be9edb51a311824b630210a9be8
pdf-font-stream PDF embedded font (sfnt) at offset 0x601F 9632 bytes