Malicious PDF — malware analysis report

Static analysis result for SHA-256 232505e195ccf33c…

MALICIOUS

PDF

49.0 KB Created: 2020-04-21 07:07:54 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 63e50842550b57c13f4378649aa7aeec SHA-1: bd6c1784068b102740d472a9dea5e2b57d505278 SHA-256: 232505e195ccf33c5d451369f65219ab6132ced8861fd2110d1c2bafa50963c4
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, many of which point to other PDF files hosted on various domains. The document body mentions 'Android calendar app that syncs with outlook', which is likely a lure to direct users to malicious websites. The heuristic 'PDF_SEO_LINK_FARM' indicates a technique to artificially inflate search engine rankings, often used for SEO spam or to host malicious content. The presence of numerous unknown-reputation URLs suggests a link farm designed to distribute or host malicious content.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pristinetintindy.com/uploads/1/3/0/2/130289641/130289641.html#android+calendar+app+that+syncs+with+outlook
    • http://ivorytowerblogger.com/uploads/1/3/0/5/130590482/gimavi.pdf
    • http://amvservicios.com/uploads/1/3/1/3/131380094/207333eb11a2b61.pdf
    • http://thehealthyurt.com/uploads/1/3/0/8/130814283/natuzozigij-mewovoxovepimol-dakejobewu-tejililamux.pdf
    • http://centerforempowerment.net/uploads/1/3/0/2/130288540/motetul.pdf
    • http://zanabeautyartistry.com/uploads/1/3/1/4/131437636/ed11434.pdf
    • http://smokenbones.net/uploads/1/3/0/6/130604244/kaxuvu.pdf
    • http://getpaidwiththeresa.com/uploads/1/3/0/7/130775806/8335d4449e1f5.pdf
    • http://eastendgreenery.ca/uploads/1/3/1/3/131398360/mivafinubameb.pdf
    • http://lisaparra.com/uploads/1/3/0/4/130489020/sebate_nitosi_pevaruzok_dowiludalipifom.pdf
    • http://nationofsteel.org/uploads/1/3/0/5/130550814/kexuxupiweposag_tudejabip_daviximisu_kisetob.pdf
    • http://eastendgreenery.ca/uploads/1/3/1/3/131398360/mivafinubam
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009867.bin
8262d5d6d29f0df0b6d71510bf5213d198e505d45f38f1a71db785309b08e39a
pdf-font-stream PDF embedded font (sfnt) at offset 0x9867 8108 bytes