Malicious PDF — malware analysis report

Static analysis result for SHA-256 86d092131de177b8…

MALICIOUS

PDF

53.0 KB Created: 2020-05-13 20:47:39 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: b99a4be7c03f34b956e8e1b60e57d9ae SHA-1: f3bf4874fcdaa20f59b307deac63fcaa2cc18548 SHA-256: 86d092131de177b896f01dc65b7c01225c75a4ebd24204c033d91daaede06b38
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which are numerically or generically named, suggesting a link farm or SEO poisoning tactic. One of the primary links directs to a page titled 'Ntr biopic 2018 songs', which is likely a lure to entice users to click through to potentially malicious content hosted on the-dollhouse-online.com. The ML classifier strongly indicated maliciousness, supporting the interpretation of this PDF as a delivery mechanism for further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://the-dollhouse-online.com/uploads/1/3/0/5/130588231/130588231.html#ntr+biopic+2018+songs
    • http://a1bakerysupplies.net/uploads/1/3/0/5/130588475/xarodego.pdf
    • http://rafflescollegelibrary.com/uploads/1/3/1/6/131606730/3363463.pdf
    • http://garagedoorrepair-sammamish-wa.com/uploads/1/3/0/4/130488691/zamifogeroz-xulosi-gafesowepowon.pdf
    • http://whenwatermeetspaint.com/uploads/1/3/1/4/131453593/dimizafupe-fanefowisezam.pdf
    • http://wonderstruckevents.com/uploads/1/3/1/4/131407310/cc0a7417f.pdf
    • http://uberrestore.com/uploads/1/3/0/6/130621809/dupojitedofipe_safapug_vubepenewejed.pdf
    • http://securehomepro.com/uploads/1/3/1/3/131398357/0b0833f.pdf
    • http://terrorsofresistance.com/uploads/1/3/0/6/130620868/4446235.pdf
    • http://hydragaming09x.com/uploads/1/3/1/3/131383383/jinosaneviz.pdf
    • http://savvyheights.com/uploads/1/3/1/4/131453175/2733841.pdf
    • http://chbrothers.net/uploads/1/3/1/4/131484090/nopunuremipiwilaz.pdf
    • http://madcarn.com/uploads/1/3/0/3/130323172/maruxegij_kuzagofiv_dizumoga_busarose.pdf
    • http://influentialblog.com/uploads/1/3/0/4/130436250/22a18.pdf
    • http://themagap.org/uploads/1/3/0/4/130490155/93cd48140b0.pdf
    • http://creativebridge.link/uploads/1/3/1/6/131606060/nokeko.pdf
    • http://matthewquinlanphotography.com/uploads/1/3/0/3/130379517/711c247e4e.pdf
    • http://exorxist.com/uploads/1/3/0/6/130620811/lukanojoj_kowitigute.pdf
    • http://renderservicesltd.com/uploads/1/3/1/4/131452949/796cf4f6ca8a6.pdf
    • http://sharpcollarmate.net/uploads/1/3/0/7/130739695/1529288.pdf
    • http://mjmsolutions.org/uploads/1/3/0/7/130739258/kufopixome.pdf
    • http://aldersonghealing.com/uploads/1/3/1/6/131637035/4942855.pdf
    • http://rollingnectar.com/uploads/1/3/0/2/130287311/dikiwavogifis.pdf
    • http://kodiakislandfoodbank.org/uploads/1/3/0/5/130589231/jufazabusedarut-jonaleluvi-jagok.pdf
    • http://modelboxed.com/uploads/1/3/1/4/131483488/9814976.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008f9e.bin
aeb56b9df10e94caad1bcfa43848e8fb43504f262a805b85e278b1e5f47a43ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F9E 5588 bytes
font_01_sfnt_off0000a2db.bin
127bfa7e6024f6761afdb8021c474c703edf5b1de3e0ef5148f80b4209edfc80
pdf-font-stream PDF embedded font (sfnt) at offset 0xA2DB 11156 bytes