Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c69962ee9749fb6…

MALICIOUS

PDF

62.2 KB Created: 2020-03-31 05:41:12 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9c74a9b8c9fe6d9dac06e52c3cb65cd9 SHA-1: 0a9650149cf6e1c3aff0285a9bd71ec871c22c1f SHA-256: 4c69962ee9749fb6323bdb757d36d0aa51d49a0ccb6fa313ca189325599f1b24
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which are numerically or generically named, suggesting a link farm designed to attract traffic. The document body contains text related to movie downloads, indicating a lure for potentially malicious content. The ML classifier strongly flagged this PDF as malicious, and the presence of numerous external URLs reinforces the assessment of a malicious link distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dnrpipelinesaustralia.com/uploads/1/3/1/3/131381891/131381891.html#chashme+baddoor+full+movie+download+bolly4u
    • http://trickonecustoms.com/uploads/1/3/0/7/130740591/renewe-wepipunisejapug-vilonojol-xezususeses.pdf
    • http://learninglotus.org/uploads/1/3/0/3/130323236/nepowojade_muvesivi.pdf
    • http://erinryanburdette.com/uploads/1/3/0/5/130588984/8dbc025a73f6d.pdf
    • http://lambertfarmslogisticspark.com/uploads/1/3/0/9/130969972/kijalazexe_xobotanapo_vuwowuzeduliz.pdf
    • http://colesmgtjournal.com/uploads/1/3/0/8/130813649/19918.pdf
    • http://rocknbeads.shop/uploads/1/3/0/7/130775466/6088060.pdf
    • http://meetformore.com/uploads/1/3/0/8/130813860/janowo.pdf
    • http://swingstatestories.com/uploads/1/3/0/9/130968926/gedef.pdf
    • http://debbymastdesigns.com/uploads/1/3/0/4/130489448/zalukimidu.pdf
    • http://weloveamericasheros.org/uploads/1/3/0/6/130621304/vodizavurodimu_nezifad_boxebopafifedap_vakadubem.pdf
    • http://dougherbilla.com/uploads/1/3/0/8/130813835/2201539.pdf
    • http://occompond.com/uploads/1/3/1/1/131164033/c7ef3f5e455e.pdf
    • http://mrsmorones.com/uploads/1/3/0/7/130776120/05ce1d8d3.pdf
    • http://fandhdesigns.com/uploads/1/3/0/5/130588221/jusevideg-tafozuxajata-fomarisederikez-xinixub.pdf
    • http://kaleidoscoperecords.net/uploads/1/3/0/5/130538816/mokinugesa.pdf
    • http://juleslifestyleretreats.com/uploads/1/3/0/4/130490056/cff08a374d6e63.pdf
    • http://shopnowgifts.com/uploads/1/3/0/3/130323298/jumutegu.pdf
    • http://traduzir-italiano.com/uploads/1/3/0/6/130603929/849634.pdf
    • http://prodbynickmang.com/uploads/1/3/0/6/130621532/pixerezasuxaz_tizalef_xawujobalu.pdf
    • http://myobsessionfixx.com/uploads/1/3/0/5/130543240/7201656.pdf
    • http://mhscarnival.com/uploads/1/3/0/6/130605198/zakanakuririwul.pdf
    • http://mentalhealthhelpforyou.org/uploads/1/3/0/5/130551399/3715884.pdf
    • http://mantissecurity.us/uploads/1/3/0/3/130323424/tenajijimixo.pdf
    • http://lasacolombia.com/uploads/1/3/0/2/130272963/wepatu.pdf
    • http://mantissecurity.us/uploads
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007843.bin
cb30ccbe3470e24abea742643761fe43cfe74664858df86eeeab0c9a4c342ab2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7843 20968 bytes
font_01_sfnt_off0000983f.bin
a4c49843c179fb4c7e3d2938e69c95871e48affc2c420949a1404ab1ce6cd029
pdf-font-stream PDF embedded font (sfnt) at offset 0x983F 8276 bytes
font_02_sfnt_off0000b846.bin
09980af06aa32beede8e777aa10233923e4f4a7e5cc0f889807f36331cd09c44
pdf-font-stream PDF embedded font (sfnt) at offset 0xB846 1584 bytes
font_03_sfnt_off0000c0d7.bin
bafd5aaf9c4ebc64667547dc5098eb02cc1bbb84856feca235901f5c51b421e7
pdf-font-stream PDF embedded font (sfnt) at offset 0xC0D7 2864 bytes
font_04_sfnt_off0000cb01.bin
1449a6a133fbba3f85fccdc8a34aa05b08b4f17ac75c7c2a9e14bb3c9634516b
pdf-font-stream PDF embedded font (sfnt) at offset 0xCB01 16060 bytes
font_05_sfnt_off0000df9b.bin
e56f5db8faf554166087922806b3819c377976d94af14c6b8a512386de68c265
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF9B 2056 bytes