Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5380bb19df3c4fc…

MALICIOUS

PDF

35.2 KB Created: 2020-04-07 07:20:28 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: a490d348336587b6c816a022e45697c2 SHA-1: 3e9a0c3919924d0137c4c660ce6b37ee28d2a741 SHA-256: e5380bb19df3c4fcfe933d54369f84adeed0998e50d8a801c3d1f15d6938fdaf
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified as a PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, contains text related to school parents and includes a URL that points to a similar structure. This suggests the document's primary purpose is to redirect users to a network of linked pages, potentially for malicious purposes such as hosting further malware or engaging in SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://strigiformae.net/uploads/1/3/0/6/130603916/130603916.html#imagenes+de+padres+de+familia+en+la+escuela
    • http://georgebroughampainting.com/uploads/1/3/0/7/130774978/jovid.pdf
    • http://purplepipes.co/uploads/1/3/0/7/130776249/1048302.pdf
    • http://blakheart.com/uploads/1/3/0/2/130270869/zewoji.pdf
    • http://crconstructioncorp.net/uploads/1/3/0/6/130604696/5615afe38b4.pdf
    • http://chicagoquinns.com/uploads/1/3/0/6/130605506/bovuzitapudaxuwole.pdf
    • http://cliffordconstruction.org/uploads/1/3/0/6/130621579/6ebaa5.pdf
    • http://clean-sweep-llc.com/uploads/1/3/0/7/130739373/76f24c79c.pdf
    • http://sarahelizabethhurley.com/uploads/1/3/0/5/130589151/4541250.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006192.bin
4800d0ad4e82a25f837af9fc1f7b84415be784ff236b5e953935b822c5acc0a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6192 7836 bytes