Malicious PDF — malware analysis report

Static analysis result for SHA-256 22e5b7f5abf3ee74…

MALICIOUS

PDF

39.0 KB Created: 2020-05-19 19:29:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8174d483f6b3af53440cf3f689f15784 SHA-1: 82f514dc80970380e09c5070e42879cc09732308 SHA-256: 22e5b7f5abf3ee749678ffd68788b8462575303dc3271d4ca6533f4e1f4d3dda
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, many of which appear to be part of a link farm designed to manipulate search engine results. The primary purpose seems to be SEO spam or redirecting users to potentially malicious content, rather than delivering a direct exploit. No scripts were extracted, limiting the ability to determine further malicious actions.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dobiehills.com/uploads/1/3/1/4/131452860/131452860.html#nesco+gardenmaster+food+dehydrator+instructions
    • http://mommyandbeeboutique.com/uploads/1/3/1/0/131070149/89226.pdf
    • http://cutekitties4u.com/uploads/1/3/0/3/130313605/4896426.pdf
    • http://ttconnection.com/uploads/1/3/0/7/130738781/goxurirokewale.pdf
    • http://d2jmusic.com/uploads/1/3/0/3/130379462/1342a872.pdf
    • http://knowledgeuniversity.org/uploads/1/3/0/9/130969042/e116d63530d1ec4.pdf
    • http://thehealthynibbler.com/uploads/1/3/0/7/130738871/monanizepiko.pdf
    • http://lisananni.com/uploads/1/3/0/5/130590126/mupek-xigugimetisu-jobasaxejir-vixameboteje.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b97.bin
b4f43a5a4a462574c8e961a0c9c294770757852ecd94a1ed4112ae41650413cf
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B97 10960 bytes