Malicious PDF — malware analysis report

Static analysis result for SHA-256 4afbb79e95ba71cd…

MALICIOUS

PDF

6.54 MB Created: 2015-05-12 01:04:57 +07:00 Authoring application: Microsoft® Office Word 2007 First seen: 2019-04-18
MD5: 73b6d099f7d8d6a1b1beaa9c4e1d481d SHA-1: 0821aea65e2b26afe4fd144b11a98eae1d0210e2 SHA-256: 4afbb79e95ba71cd694ccf39ffc527875a658e0bc04df3c22171e03ca4c1ffdb
182 Risk Score

Malware Insights

MITRE ATT&CK
T1204.001 Malicious Link T1566.002 Spearphishing Attachment

The document exhibits characteristics of an advance-fee scam and a browser installation lure. It contains language suggesting a lottery or prize, combined with requirements for parcel delivery, aligning with advance-fee fraud. Furthermore, it prompts the user to install a browser extension or update, a common tactic for credential theft or malware delivery. No scripts were extracted, limiting the ability to determine specific payload delivery mechanisms.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6280

Heuristics 6

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: https://www.safaribooksonline.com/library/view/hacking-web-intelligence/9780128018675/XHTML/cover.xhtml#cover.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://http/www.sourceforge.net/projects/chromium In PDF document text
    • http://https/www.epicbrowser.com/In PDF document text
    • http://http/www.hcon.in/downloads.htmlIn PDF document text
    • http://http/www.getmantra.com/In PDF document text
    • http://www.getmantra.com/download.htmlIn PDF document text
    • http://www.getmantra.com/mantra-on-chromium.htmlIn PDF document text
    • http://firecat.toolswatch.org/download.htmlIn PDF document text
    • http://https/www.whitehatsec.com/aviator/In PDF document text
    • http://https/www.torproject.org/projects/torbrowser.html.enIn PDF document text
    • http://digitalinspiration.com/google-ChromeIn PDF document text
    • http://www.polymeta.com/In PDF document text
    • https://ixquick-proxy.com/In PDF document text
    • https://pipl.com/In PDF document text
    • http://www.yasni.com/In PDF document text
    • http://www.marketvisual.com/In PDF document text
    • http://theyrule.net/In PDF document text
    • http://www.emailsherlock.com/In PDF document text
    • http://www.usersherlock.com/In PDF document text
    • http://checkusernames.com/In PDF document text
    • http://namechk.com/In PDF document text
    • http://knowem.com/In PDF document text
    • http://kngine.com/In PDF document text
    • http://www.example.com���In PDF document text
    • http://www.hcon.in/downloads.htmlIn PDF document text
    • http://www.getmantra.com/In PDF document text
    • http://www.getmantra.com/mantra-on-In PDF document text
    • https://www.whitehatsec.com/aviator/In PDF document text
    • https://ixquick-proxy.comIn PDF document text
    • http://www.social-searcher.com/In PDF document text
    • http://trendsmap.com/In PDF document text
    • http://tweetbeep.com/In PDF document text
    • http://twiangulate.com/searchIn PDF document text
    • http://nerdydata.comIn PDF document text
    • https://search.nerdydata.com/In PDF document text
    • https://searchcode.comIn PDF document text
    • https://w3dt.net/In PDF document text
    • http://www.shodanhq.com/In PDF document text
    • http://www.ImageRaider.com/In PDF document text
    • http://datamarket.com/In PDF document text
    • http://datamarket.com/topic/list/In PDF document text
    • http://addictomatic.comIn PDF document text
    • http://search.carrot2.org/stable/searchIn PDF document text
    • http://search.carrot2.org/In PDF document text
    • http://project.carrot2.org/download.htmlIn PDF document text
    • http://boardreader.com/In PDF document text
    • http://omgili.com/In PDF document text
    • http://www.sensebot.net/In PDF document text
    • http://www.whostalkin.com/In PDF document text
    • http://mentionmapp.com/In PDF document text
    • http://socialcollider.net/In PDF document text
    +387 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_140_off005acb59.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5ACB59 223912 bytes
SHA-256: 9d3d57961bd65ca6fec4ff9c8226aa79777215cef17aa9f9bac87c5366d570a8
stream_141_off005cbeb1.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5CBEB1 218888 bytes
SHA-256: 81b63288142224a69b53d8805eab6e76229c3ba3c35932cfd5af8a08d0188f9b
stream_144_off005ff66d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5FF66D 200100 bytes
SHA-256: 2de5e78140f9a430330b2398f731a4b04907785d96283ea4d3948512227c082e