Malicious PDF — malware analysis report

Static analysis result for SHA-256 87dfb60bf64719f8…

MALICIOUS

PDF

50.7 KB Created: 2020-04-02 07:14:58 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: ad983ed43934b6370b5f6e1ac85ca350 SHA-1: f6958a9d79b64d8ef0511f5a1c9e1fd8a5c8e007 SHA-256: 87dfb60bf64719f83e1aba659c2219ac4372107c7d6e449058a9177f2943950c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which are numerically or generically named, suggesting a link farm designed to attract search engine traffic. One prominent link lures users with the promise of watching a movie online, which is a common social engineering tactic. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the extensive link farm and the deceptive content point towards a malicious distribution or phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bigbiz.app/uploads/1/3/0/7/130740056/130740056.html#diary+of+a+wimpy+kid+movie+the+long+haul+watch+online+free
    • http://rnbkennel.com/uploads/1/3/1/3/131398574/3322081.pdf
    • http://bennetteducationalconsulting.com/uploads/1/3/0/6/130604860/56fd044e16d.pdf
    • http://fansteamslegends.com/uploads/1/3/0/8/130873994/b9f931484eb.pdf
    • http://randmc2019.com/uploads/1/3/1/4/131408502/3895958.pdf
    • http://ukhorseboxhire.com/uploads/1/3/0/2/130289313/vopedetenala-nivabepodapo.pdf
    • http://happyfishsoap.com/uploads/1/3/0/4/130483561/sixoxikaf_riruxizubew_rebilasutu_zedibifodoso.pdf
    • http://jpena-art.com/uploads/1/3/1/3/131383493/voxejozisulaj_seloz.pdf
    • http://integrityestateplanning.com/uploads/1/3/0/4/130478484/602753.pdf
    • http://technobubble.app/uploads/1/3/0/9/130968985/vatolirurom.pdf
    • http://auggiehomebuyers.com/uploads/1/3/0/7/130774994/lazavulurujek.pdf
    • http://bardnurseries.net/uploads/1/3/0/5/130590168/wuxuzufojawukig_zujetidilajixik.pdf
    • http://crcid.net/uploads/1/3/1/4/131452876/4048728.pdf
    • http://veganergenuss.org/uploads/1/3/0/7/130739163/ropexuwek_jukezefukazan_xajibepakub.pdf
    • http://glamdecorbx.com/uploads/1/3/0/7/130776415/4adb603c4e.pdf
    • http://josephmarshpowerwashing.com/uploads/1/3/0/6/130604884/vuxobugunuf-vakuvipafitotuj-wajara-mokapoduk.pdf
    • http://cocreativ.org/uploads/1/3/1/1/131164266/tukum.pdf
    • http://honeysisterboutique.com/uploads/1/3/0/4/130476720/wuranorapefek_xejeloma.pdf
    • http://michaelaldenofficial.com/uploads/1/3/0/6/130605149/60314.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off0000998e.bin
f0e06e0c7ede7d0ed17d501d10d070d5081dc1decb47368f44f8fa7a131d5d39
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x998E 20092 bytes
font_00_sfnt_off0000707f.bin
13e65ced2193f023efe01aa6a99d1841603cac5b8faeec331bcbb1f7b52ca537
pdf-font-stream PDF embedded font (sfnt) at offset 0x707F 8252 bytes
font_01_sfnt_off0000905b.bin
83d89f79375f7f339e88070a8779324ce221c94923bff415e388e162fbc46cfe
pdf-font-stream PDF embedded font (sfnt) at offset 0x905B 2604 bytes