Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f8aa36cd9d6effb…

MALICIOUS

PDF

49.7 KB Created: 2020-06-04 06:43:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 966ba3dc42efbd080999dc6d5224a1cd SHA-1: a5455a945e11af3563a08203daec3d75e151152e SHA-256: 1f8aa36cd9d6effb96ec8c75d92da7e70b554803762657052e5c05c960d1d212
62 Risk Score

Malware Insights

MITRE ATT&CK
T1598 External Remote Services T1204 User Execution

The PDF file contains a large number of external links, characteristic of a link farm or SEO spam. The primary heuristic identified a mass of external PDF links hosted on various domains, suggesting an attempt to manipulate search engine results or redirect users to potentially malicious content. The document body contains garbled text and metadata, but the presence of the URL 'http://sunshinebehavioralhealthllc.com/uploads/1/3/0/7/130739927/130739927.html#tatuajes+de+dios+en+el+brazo' is notable.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sunshinebehavioralhealthllc.com/uploads/1/3/0/7/130739927/130739927.html#tatuajes+de+dios+en+el+brazo
    • http://learnenglishspellingrules.com/uploads/1/3/0/4/130488940/fc77cd.pdf
    • http://musicaware.org/uploads/1/3/0/6/130640031/6868107.pdf
    • http://corcoranbottleshop.com/uploads/1/3/0/4/130479570/wasaris-wukipitabukamir.pdf
    • http://hostmaster.hornadaybsa.org/uploads/1/3/1/6/131606144/4857040.pdf
    • http://arteducatorsofiowa.org/uploads/1/3/0/5/130551962/sotutofixugi-mofumujadosoxi-nesilez.pdf
    • http://dobiehills.com/uploads/1/3/1/3/131379268/87a3d2470b587.pdf
    • http://thegallerydifferent.com/uploads/1/3/0/5/130551405/1237444.pdf
    • http://villaforsaleandalucia.com/uploads/1/3/1/4/131453574/wukumeturomexop.pdf
    • http://sunshinebehavioralhealthllc.com/uploads/1/3/0/7/130739927/terms.html
    • http://sunshinebehavioralhealthllc.com/uploads/1/3/0/7/130739927/dmca.html
    • http://sunshinebehavioralhealthllc.com/uploads/1/3/0/7/130739927/policy.html
    • http://dobiehills.com/uploads/1/3/1/3/131379268/87a3d2470b587
    • https://jewokiwisaze.files.wordpress.com/2020/06/60718767243.pdf
    • https://lunudosur.files.wordpress.com/2020/06/nifenekekifevizedenu.pdf
    • https://nigurite622001163.files.wordpress.com/2020/06/bewefenesofinepito.pdf
    • https://jugotidosej.files.wordpress.com/2020/06/55253547327.pdf
    • https://rusevaleno.files.wordpress.com/2020/06/wutekomebuvafawege.pdf
    • https://tejigag564805948.files.wordpress.com/2020/06/14973591091.pdf
    • https://zusanudez.files.wordpress.com/2020/06/63047631797.pdf
    • https://pegepev.files.wordpress.com/2020/06/tiketokomidevuligufi.pdf
    • https://zokagumitof.files.wordpress.com/2020/06/femibigivoledovuju.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000095ad.bin
3755be5ebd0c07771effebbfd96f35aa91adeba5772fe34405ba375497792e01
pdf-font-stream PDF embedded font (sfnt) at offset 0x95AD 11468 bytes