Malicious PDF — malware analysis report

Static analysis result for SHA-256 25954f0d128fc87e…

MALICIOUS

PDF

36.9 KB Created: 2020-03-12 07:10:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 9236efe0c073f69b1f1ba3226b9356af SHA-1: 15ef00f80afb1a0d22949547a821ea8b23765718 SHA-256: 25954f0d128fc87e94ed56946cae359e98fc6d9301fadce7ed5802e75eaa1a13
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious sites. The document body itself is heavily obfuscated but contains references to the URLs, suggesting a deliberate attempt to drive traffic to these external resources. No scripts were extracted, and the primary malicious behavior observed is the extensive link farm.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bet365yulechengwangzhi.br3h.com/uploads/1/3/0/2/130288753/130288753.html#how+to+do+axonometric+in+revit
    • http://www.pchstv.org/uploads/1/3/0/6/130621385/rojerib_tafil_xirexedajo_dimopav.pdf
    • http://glambyrena.com/uploads/1/3/0/5/130539072/1607f6.pdf
    • http://movingmindsdance.com/uploads/1/3/0/4/130436145/wosipit.pdf
    • http://csoenterprisesinc.com/uploads/1/3/0/4/130435596/c09bad.pdf
    • http://porscheaphotography.com/uploads/1/3/0/8/130813618/sebak.pdf
    • http://fultoncountyconservationdistrict.com/uploads/1/3/0/2/130271078/4318666.pdf
    • http://www.newcanaanlakesidechateau.com/uploads/1/3/0/6/130639347/ed48b.pdf
    • http://electricianmartincounty.com/uploads/1/3/0/5/130550874/vagigajoruzatul.pdf
    • http://www.dmjmasonrywny.com/uploads/1/3/0/6/130620508/zoveruluj.pdf
    • http://mail.zucht-niesenblick.ch/uploads/1/3/0/3/130313404/2247435.pdf
    • http://adobedelsolpropertysolutions.com/uploads/1/3/0/6/130621892/6312487.pdf
    • http://electkt.com/uploads/1/3/0/7/130775845/7069024.pdf
    • http://alphaperformance.ca/uploads/1/3/0/8/130874540/dowaduxo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006a95.bin
d9e7f296ff9a6364bf768cccec77328b18d9dbb5b7cf9d6df07ef0f3376d41bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A95 7096 bytes