Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8e8eba7f4c9c607…

MALICIOUS

PDF

63.6 KB Created: 2020-03-14 23:43:51 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 970fc8b668b5fddc3b13c531c8cf1f48 SHA-1: 5a071e38bb1c85716f3a09bb46db19b1b4cbe238 SHA-256: c8e8eba7f4c9c6079c8550b823846060e791830a7d892c08297a9f78de8b852c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which are dynamically generated and point to potentially malicious content. The document body mentions 'Camille guide league of legends', suggesting a lure to attract users. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass external link farm, and the ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves tricking users into visiting these external links, which likely host further malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jindubaijiale.br3h.com/uploads/1/3/0/4/130491418/130491418.html#camille+guide+league+of+legends
    • http://hostmaster.ivyleaguenursery.com/uploads/1/3/0/7/130776279/patufo-mujapalugipu-sawemaw-pawozisolojekom.pdf
    • http://mmconstruction.eu/uploads/1/3/0/7/130739684/3888396.pdf
    • http://513free.net/uploads/1/3/0/7/130739864/9289396.pdf
    • http://assistancedogassociation.org/uploads/1/3/0/3/130313150/tusimod-dikazudewenit-xilefazavusige.pdf
    • http://www.dronehubonline.com/uploads/1/3/0/6/130604046/653d632a7f5a183.pdf
    • http://www.hodkinsongardendesign.com/uploads/1/3/0/5/130539652/vanagelesusavinu.pdf
    • http://gabrielledrouin.com/uploads/1/3/0/5/130590325/taniwivokalowepobil.pdf
    • http://cuiwenqing.com/uploads/1/3/0/7/130738740/bdfa9.pdf
    • http://abogadoquiebraspuertorico.com/uploads/1/3/0/6/130621309/divor.pdf
    • http://www.bloomingwisdombydana.com/uploads/1/3/0/2/130289702/nokifejiwi.pdf
    • http://jesseslandscapingma.com/uploads/1/3/0/6/130603985/vinanej_ronaralegi_kakukul_tokib.pdf
    • http://allysings.com/uploads/1/3/1/0/131070645/c9c40d8e781744.pdf
    • http://enterprisesoftwarealternatives.com/uploads/1/3/0/6/130621864/81ce05.pdf
    • http://yrccoolers.com/uploads/1/3/0/4/130483799/7949842.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c4d0.bin
12bd06925edc2a67a14ffec6bc5873227dcfd908a09ad707717857071bda1692
pdf-font-stream PDF embedded font (sfnt) at offset 0xC4D0 8384 bytes
font_01_sfnt_off0000e50d.bin
267cf351bf1c0eb97668df725043b446cd79494ad2a145e4e6366c7751e1a5e7
pdf-font-stream PDF embedded font (sfnt) at offset 0xE50D 2608 bytes