Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ffbacacf3cfa0d6…

MALICIOUS

PDF

37.3 KB Created: 2020-05-14 18:18:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9e878b53b98bf1fd49e583a6ecc8d501 SHA-1: ec3726468be3cb39ed8caeec049106c60229cf7f SHA-256: 8ffbacacf3cfa0d65ede26d15b4654bc4ccbe8df4192da322a63d8c0af0e3f5c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous external links, a technique often used for SEO poisoning or to redirect users to malicious sites. The document body, though heavily obfuscated, contains text related to 'piano sheet music' and the URLs themselves follow a pattern indicative of a link farm. The ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves luring the user to one of the many external URLs, likely for phishing or to serve a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://clearhomeuk.com/uploads/1/3/0/7/130776006/130776006.html#locked+out+of+heaven+piano+sheet+music
    • http://talesofatravelingnurse.com/uploads/1/3/0/6/130603834/4917642.pdf
    • http://abetterbadgercare.com/uploads/1/3/0/7/130739951/7058479.pdf
    • http://thefragrancekingdom.com/uploads/1/3/1/4/131483065/fixulotagel.pdf
    • http://purpleoctober.com/uploads/1/3/0/6/130603824/pewowime-vunuje-danezuvesisat.pdf
    • http://urbanizacion.info/uploads/1/3/0/9/130969406/b2f1be240e37.pdf
    • http://championlearnershub.com/uploads/1/3/1/4/131413418/sewidukudalimegij.pdf
    • http://bostonbigscreens.com/uploads/1/3/1/4/131438556/livenixi_jarafopuwatave.pdf
    • http://polinagavria.com/uploads/1/3/1/0/131070695/1a7a3.pdf
    • http://massageadventures.net/uploads/1/3/0/4/130476642/bebam.pdf
    • http://countrysidehomes.net/uploads/1/3/1/4/131453927/zumevajavoga_limirives_sopovum.pdf
    • http://plussizeweddingdressmassachusetts.com/uploads/1/3/0/6/130604621/3930332.pdf
    • http://tedchin.com/uploads/1/3/1/4/131452836/70fc4f6c3.pdf
    • http://plndstore.com/uploads/1/3/1/6/131636719/novur-povamamir-sijomogukijunu-kegefuvudi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005df2.bin
f4d7f02c393d68aeae74018ac4426d6178eac85d2e1906a4f0615ff89bbbd8c7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DF2 13600 bytes