Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b10349bf5b1ea12…

MALICIOUS

PDF

73.8 KB Created: 2020-04-01 20:13:28 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 3f4e86f537dda67b61a22b0a697c2c07 SHA-1: a2641edb937bec12c5223a152f762e9daeebc490 SHA-256: 1b10349bf5b1ea12785b6184b0f9d8c52ac0a4236c38ea2888276405d6273099
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The embedded document body text, though partially corrupted, includes a URL that is also present in the list of extracted URLs. This suggests the primary function of this PDF is to act as a link farm, potentially for SEO manipulation or to direct users to malicious websites.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lbtherapy.org/uploads/1/3/0/6/130620525/130620525.html#electrocardiograma+normal+y+anormalidades+durante+el+cateterismo+cardiaco
    • http://isisserviciosconsultores.com/uploads/1/3/0/7/130776687/xekinoravove_ramotulejubukib_mazudetufumejag.pdf
    • http://frontiertitansbaseball.com/uploads/1/3/0/5/130539659/7474949.pdf
    • http://ftbk.net/uploads/1/3/0/5/130589276/loxidojuduzisusupi.pdf
    • http://hoosierpadre.com/uploads/1/3/0/6/130639886/eeea5e5eec16a44.pdf
    • http://applecommercialre.com/uploads/1/3/0/4/130475959/1866239.pdf
    • http://diamondsuppliments.com/uploads/1/3/0/9/130969056/zetexetujonez.pdf
    • http://alliancetranscription.org/uploads/1/3/0/6/130605212/9298587.pdf
    • http://ommammayoga.ca/uploads/1/3/0/2/130272577/takukeko_baviw.pdf
    • http://opscollc.com/uploads/1/3/0/5/130545087/voguxiripituf.pdf
    • http://sloanemorocco-efolio.com/uploads/1/3/0/6/130620813/vuzisojofolefitowira.pdf
    • http://rollinwithflavor.com/uploads/1/3/0/6/130640021/4688990.pdf
    • http://personaltrainingzurich.com/uploads/1/3/0/5/130545382/9523599.pdf
    • http://courtesyrealtygroup.net/uploads/1/3/0/6/130620471/ginememufugilo_limana_monikelelezaje.pdf
    • http://skbequine.com/uploads/1/3/1/0/131071157/netef-dikotoluguwiruj-pekajelem-gaxoxazufi.pdf
    • http://forcew.com/uploads/1/3/0/8/130814669/kefopum.pdf
    • http://ourhealthykingdom.com/uploads/1/3/0/3/130323437/jemudoruxudo-gazetamepija.pdf
    • http://mikalsmountainco.com/uploads/1/3/1/0/131071164/ruganimajojoroweb.pdf
    • http://mastertoken.net/uploads/1/3/0/7/130775497/60a3c9549e.pdf
    • http://bonkerforbyram.com/uploads/1/3/0/6/130621409/2880887.pdf
    • http://internationalclimatechange.com/uploads/1/3/0/7/130738861/bfa69a.pdf
    • http://chipperentertainment.com/uploads/1/3/0/2/130288326/kapidi_peboge_sozexirowu_lobipalan.pdf
    • http://zoliandrico.com/uploads/1/3/0/5/130588343/zaxix_putefewanomos_pakumelexav.pdf
    • http://thefiberfaerie.com/uploads/1/3/0/5/130550824/mufulexinakoxaza.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f68f.bin
315b450774295d122419a0ec2375d156db75f2b7c5c48c4d9980780b35f62a63
pdf-font-stream PDF embedded font (sfnt) at offset 0xF68F 9316 bytes