Malicious PDF — malware analysis report

Static analysis result for SHA-256 1be423da20d3579d…

MALICIOUS

PDF

64.3 KB Created: 2020-06-09 08:10:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 92b174ad29997cf106e8c753b12390c5 SHA-1: 00b756b2039d7daab4c940cbc5055187e4c8cd2b SHA-256: 1be423da20d3579da8d6cad64c07162a66b47b33da11b31f5f843abbf27bd506
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of external links, identified as a PDF link farm. The primary purpose appears to be SEO spam or directing users to potentially malicious content hosted on various domains. No scripts were extracted, limiting the analysis of direct payload execution. The presence of numerous external links suggests a social engineering or redirection-based attack vector.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://therileyrecruit.com/uploads/1/3/1/6/131637432/131637432.html#%25D8%25A7%25D9%2584%25D8%25A3%25D8%25B1%25D8%25B5%25D8%25A7%25D8%25AF+%25D8%25A7%25D9%2584%25D8%25AC%25D9%2588%25D9%258A%25D8%25A9+%25D8%25B3%25D8%25A7%25D9%2586%25D8%25AA+%25D8%25AC%25D8%25A7%25D9%2586+%25D9%2583%25D8%25A7%25D8%25A8+%25D9%2581%25D9%258A%25D8%25B1%25D8%25A7%25D8%25AA+%25D9%2581%25D8%25B1
    • http://theimsonline.com/uploads/1/3/1/8/131872149/7597325.pdf
    • http://mail.broadripplecandle.com/uploads/1/3/0/3/130313466/719d612ea082.pdf
    • http://webdisk.brisbaneantennaprofessionals.com/uploads/1/3/1/4/131454452/5248473.pdf
    • http://dev.poliglow-int.com/uploads/1/3/0/3/130379814/f06792466e.pdf
    • http://addesignsllc.com/uploads/1/3/0/9/130969833/280883.pdf
    • http://hostmaster.markdoodesplanning.co.uk/uploads/1/3/0/7/130740050/gefawamalozuliw_gopow_zobinutusife_minada.pdf
    • http://mtlspeechtherapy.com/uploads/1/3/2/3/132303093/84860be6d33.pdf
    • http://shineaccountants.com.au/uploads/1/3/1/4/131438151/5b9823d7e42b27f.pdf
    • http://uabadmontas.com/uploads/1/3/0/6/130604372/30de0c.pdf
    • http://shopcharlienewyork.com/uploads/1/3/1/6/131636824/a0c36134a741.pdf
    • http://partybikebusiness.com/uploads/1/3/0/2/130289474/2521542.pdf
    • http://anaxeandagun.com/uploads/1/3/1/4/131406109/xagazilodexipen.pdf
    • https://fimesijonoba.files.wordpress.com/2020/06/65623859415.pdf
    • https://vobadir.files.wordpress.com/2020/06/saposigoxe.pdf
    • https://daguxazogas.files.wordpress.com/2020/06/janujanejujewexigen.pdf
    • https://redejoxas.files.wordpress.com/2020/06/rizokefexujevolej.pdf
    • https://mijawodemim.files.wordpress.com/2020/06/59913766402.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00009dbe.bin
96b8adbb4b6c27789aa1e4192f477c8585fb96e6918891680d7d328c34b71d24
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9DBE 31628 bytes
font_01_sfnt_off0000d4c3.bin
4ddeb6cb05688e75070cd698832ccbea8777abd73a8fdc5a99e22f0b3580ed6d
pdf-font-stream PDF embedded font (sfnt) at offset 0xD4C3 8508 bytes