Malicious PDF — malware analysis report

Static analysis result for SHA-256 8fb86feadcea582d…

MALICIOUS

PDF

27.4 KB Created: 2020-04-20 17:48:12 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: dfdaa9bf815f298fd0506ec0e6120707 SHA-1: 181e1c7d3d24d77e68bfd1fa9cf57593d8c1a486 SHA-256: 8fb86feadcea582ddcea3ed48e91788e981502b2c571a59d476ec51ef025d548
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of external links, identified as a PDF_SEO_LINK_FARM heuristic. The document body, though heavily obfuscated, contains references to 'Ashampoo burning studio free' and 'wkhtmltopdf', suggesting a potential lure or disguise. The primary attack pattern involves directing users to a network of related domains, likely to host further malicious content or engage in SEO spam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9193

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://scrivenerpress.com/uploads/1/3/0/7/130775649/130775649.html#ashampoo+burning+studio+free
    • http://lookingatplants.com/uploads/1/3/0/5/130545199/f09beacf6.pdf
    • http://weddingness.com/uploads/1/3/0/3/130379216/fejuxuxeleroza-tarajelabirozew-wojalerexegaxub.pdf
    • http://kewbridgewest.net/uploads/1/3/0/8/130873937/9911971.pdf
    • http://lysop.com/uploads/1/3/0/8/130874156/basumisew.pdf
    • http://4fresh2o.com/uploads/1/3/0/6/130605212/7916547.pdf
    • http://theorogen.com/uploads/1/3/0/5/130588679/9602656.pdf
    • http://stemusings.com/uploads/1/3/0/5/130590158/govifagukura_bukapejijaduwit.pdf