Malicious PDF — malware analysis report

Static analysis result for SHA-256 f956e1062f1f60aa…

MALICIOUS

PDF

55.1 KB Created: 2020-03-30 05:38:45 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: be32465e6cae5583dc9531c0328c9035 SHA-1: 34ca3192249d5af5d0c73bfabec54d8521afe55f SHA-256: f956e1062f1f60aa7ac43beb9dfabcb0a45c3afaa912273ca0c7e5b2d29cf433
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

This PDF document contains a large number of external links, a technique often used for SEO spam or to redirect users to malicious sites. The ML classifier strongly indicated maliciousness. The document body contains garbled text and what appears to be metadata, but the primary malicious activity is the mass distribution of external URLs. No scripts were extracted, limiting the ability to determine further payload delivery or persistence mechanisms.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://northernrailleaders.com/uploads/1/3/1/0/131070452/131070452.html#fase+secretora+ciclo+endometrial
    • http://chassjoyfitnessparty.com/uploads/1/3/0/2/130287242/simulesizumab.pdf
    • http://pynluv.com/uploads/1/3/0/5/130551927/dezuvekok.pdf
    • http://pristinebeautyclub.com/uploads/1/3/0/7/130776257/fc93804d95.pdf
    • http://graevesauto.com/uploads/1/3/0/9/130968931/godeb.pdf
    • http://wcscustom.com/uploads/1/3/0/7/130775797/0f12348c.pdf
    • http://lamariposatexas.com/uploads/1/3/0/5/130550869/a5bf2.pdf
    • http://debbies-prayer.com/uploads/1/3/0/3/130323493/41b355556738.pdf
    • http://www.hernandezforclay.com/uploads/1/3/0/9/130969568/zapevilele.pdf
    • http://refi-llc.net/uploads/1/3/1/3/131380453/sufuzojewikuvepetup.pdf
    • http://kathydwyer.com.au/uploads/1/3/0/6/130605034/jedidofaturivobiv.pdf
    • http://motorclub365.us/uploads/1/3/0/3/130379347/zugelanoribe_xarodovufarar_zamomunukusutus_nobugozogozak.pdf
    • http://neverlandcostarica.com/uploads/1/3/0/5/130539637/4d33ea.pdf
    • http://refsrock.com/uploads/1/3/0/8/130813784/xoduwuzaneki.pdf
    • http://fe-corporation.com/uploads/1/3/0/4/130488446/vukod.pdf
    • http://jbjanitorialserices.com/uploads/1/3/0/4/130483550/5504811.pdf
    • http://myhallaway.com/uploads/1/3/1/4/131409148/zonakifojojukim.pdf
    • http://philadelphon.org/uploads/1/3/0/7/130776743/nalewa-sixularezud.pdf
    • http://bushyidoc.com/uploads/1/3/1/4/131453260/finexaxife.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000074a2.bin
48f41a311023c3bbce9bb73014182d4b55618413203cd0e797e063d9da8d5a73
pdf-font-stream PDF embedded font (sfnt) at offset 0x74A2 6576 bytes
font_01_sfnt_off000084b7.bin
bea69841bbd46f04639925fa9e638b9454a63fc505ebcc989a5b8e18d31d632e
pdf-font-stream PDF embedded font (sfnt) at offset 0x84B7 9876 bytes
font_02_sfnt_off0000a78d.bin
99a9c3fedc6a80628b6557ab027077f7002b0e2d8275dfd6e1bc181ced4cc29d
pdf-font-stream PDF embedded font (sfnt) at offset 0xA78D 4072 bytes
font_03_sfnt_off0000b598.bin
07e30919570e33b20c4f5ffeb099b7662403a71ac0a813d1a20e0b482f8bd043
pdf-font-stream PDF embedded font (sfnt) at offset 0xB598 16416 bytes