Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f33ab3e681cc1c5…

MALICIOUS

PDF

41.2 KB Created: 2020-05-12 23:40:52 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 61606c313420dc204ba251de99f0166b SHA-1: 50135ecfb491fe9dd18df166f54823948b5e9c69 SHA-256: 1f33ab3e681cc1c5debadda297f729a6df85c1e50e2cb218c86c518fb5dcbbb1
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection to malicious sites. The presence of a QR code lure (SE_QR_LURE) further indicates an attempt to direct user interaction, likely towards these external resources. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of specific payloads.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://allanali.com/uploads/1/3/0/2/130289675/130289675.html#android+hdr+camera+app+test
    • http://leddesertwhips.com/uploads/1/3/1/6/131607445/pedovipaboxus.pdf
    • http://ahmanique.net/uploads/1/3/0/4/130488181/e4295e4e88c25c.pdf
    • http://piecebypiecestudios.com/uploads/1/3/1/0/131070381/49d1702bb54afd.pdf
    • http://masterlinkdevelopment.com/uploads/1/3/1/4/131437293/144dda7b40e4.pdf
    • http://prodam-berlin.com/uploads/1/3/0/6/130640219/gijafesofo_xiled_sibaw_tonixuxebomef.pdf
    • http://theidealorganization.com/uploads/1/3/1/4/131409210/molizojili.pdf
    • http://n-e-s.dev/uploads/1/3/1/1/131163876/zodewojoxen.pdf
    • http://jovial.store/uploads/1/3/0/2/130287503/bexuverudazakoja.pdf
    • http://janipepelanov.com/uploads/1/3/0/5/130540219/fetubawam.pdf
    • http://americanbeachtour.com/uploads/1/3/0/6/130640144/favara.pdf
    • http://primestiching.com/uploads/1/3/0/4/130476040/5064021.pdf
    • http://fotografiamajooper.com/uploads/1/3/0/5/130539886/wedujetukumumu-sanomewozakig.pdf
    • http://tszclan.com/uploads/1/3/0/7/130739107/8019119.pdf
    • http://gab-archive.org/uploads/1/3/0/5/130551057/kasazinif.pdf
    • http://flavorstw.com/uploads/1/3/0/9/130969332/pebajilosevibokedi.pdf
    • http://artshopp.com/uploads/1/3/0/7/130739835/9929097.pdf
    • http://catalystlightandsound.com/uploads/1/3/0/2/130288523/rezotapel_jabufebuxila.pdf
    • http://haitiandbeyond.com/uploads/1/3/1/4/131406154/5217805.pdf
    • http://driftawayvacations.net/uploads/1/3/1/1/131164562/2049583.pdf
    • http://2dinvestsarl.com/uploads/1/3/1/4/131454178/nodelo.pdf
    • http://northerncoloradofarrier.com/uploads/1/3/0/8/130814681/rasar.pdf
    • http://gridhop.net/uploads/1/3/0/7/130775702/lexaruvipemup.pdf
    • http://pianowithjamie.com/uploads/1/3/0/5/130590589/fulamuvudomosuz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000758e.bin
eeab48c98416448218fcf36b6f408faa8d11356db8e278bb101a117ee755f988
pdf-font-stream PDF embedded font (sfnt) at offset 0x758E 10328 bytes