Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5e009d728ac0bab…

MALICIOUS

PDF

26.8 KB Created: 2020-04-14 11:07:43 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9aa1dc0ed3bb8f3821486d81d305c14f SHA-1: e5ddf4c988e20a9ed75e4e166dc0beca13db7c6f SHA-256: d5e009d728ac0bab32691b54822dccf3509b821665013433c259adff12faf8cb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a large number of external links, many of which point to similarly structured URLs on different domains. This pattern is indicative of a link farm or SEO spam campaign, designed to drive traffic to potentially malicious sites. The document body contains garbled text but includes a reference to 'Candy camera new version app', suggesting a lure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9179

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seacretsofpopponesset.com/uploads/1/3/0/4/130476062/130476062.html#candy+camera+new+version+app
    • http://duivictimlaw.com/uploads/1/3/1/4/131454766/zulokuxigetize.pdf
    • http://lvhalo.com/uploads/1/3/0/7/130740010/jomejawukojo-katatexamel.pdf
    • http://fintradeadvisorsllc.com/uploads/1/3/0/6/130639740/muxuwovu.pdf
    • http://marleysbarcatering.com/uploads/1/3/0/7/130739204/8826493.pdf
    • http://wavesmediagroup.com/uploads/1/3/0/2/130270895/9518877.pdf
    • http://lightz-sparks.net/uploads/1/3/0/4/130483266/638712.pdf
    • http://good-neighbor-network.net/uploads/1/3/0/6/130604791/6bcab499d.pdf