Malicious PDF — malware analysis report

Static analysis result for SHA-256 2fdf9aa41566e26d…

MALICIOUS

PDF

18.2 KB Created: 2020-05-19 10:20:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f796847a1019d1a7b8f1083f40595eeb SHA-1: 1c48add06c09a7a6c86916b75766fb117290b7a6 SHA-256: 2fdf9aa41566e26d05cc2a642196322f809d15846ef245a19eda3efd78982b62
112 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF is identified as an image-only lure, typical of phishing campaigns. It contains numerous external links, suggesting a link farm designed to distribute traffic to various malicious sites. The primary URL, http://shortsaleproteam.com/uploads/1/3/1/3/131380594/131380594.html#childhood%2527s+end+find+hyperion+rkt+sentry, is likely the initial point of contact for the user. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 18 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://shortsaleproteam.com/uploads/1/3/1/3/131380594/131380594.html#childhood%2527s+end+find+hyperion+rkt+sentry
    • http://wendyfwilliams.net/uploads/1/3/1/3/131380316/1535392.pdf
    • http://saintsgomarchingfilm.com/uploads/1/3/1/8/131856032/753768.pdf
    • http://robi-anderson-edu.com/uploads/1/3/0/2/130287943/9e5ddfa3.pdf
    • http://zofitnesswear.com/uploads/1/3/0/4/130488417/433762.pdf
    • http://andrewphamcoaching.com/uploads/1/3/0/7/130740086/mofunopujejidoteto.pdf
    • http://collincurry.com/uploads/1/3/0/6/130604379/9543576.pdf
    • http://truthfuldata.net/uploads/1/3/0/6/130622002/bujuvenunof_liboredorirowu_gawodi_rujebamipawaxuk.pdf
    • http://randombuyers.org/uploads/1/3/1/0/131070382/b8b45959bdb206.pdf
    • http://muctieuchinhxac.com/uploads/1/3/1/4/131437198/5277a2e.pdf
    • http://bettyswaner.org/uploads/1/3/1/6/131636743/77beae1e742.pdf