Malicious PDF — malware analysis report

Static analysis result for SHA-256 25aed634ca3c7dd4…

MALICIOUS

PDF

43.1 KB Created: 2020-03-09 02:41:49 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 400403babb456450b51ea41c844e2103 SHA-1: cd64e1c412a56067f02c2d109338a633b7b8ea4f SHA-256: 25aed634ca3c7dd432a54b0081a16641fb337754bcdc908f9a0fdc51eecac125
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to similarly structured URLs on different domains. The document body text, though heavily obfuscated, contains references to inserting text boxes in PDFs and includes several of these external URLs. This suggests a link farm or SEO poisoning tactic designed to drive traffic to potentially malicious sites.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://xianjinduboyouxi.br3h.com/uploads/1/3/0/5/130551130/130551130.html#insert+text+box+in+pdf+file
    • http://anzics2019.nz/uploads/1/3/0/2/130270971/jasalafebokabegelup.pdf
    • http://carsforfood.com/uploads/1/3/0/7/130776478/218a0.pdf
    • http://webmail.livestyliv.com/uploads/1/3/0/6/130603916/1678712.pdf
    • http://projectdreamport.info/uploads/1/3/0/8/130813366/3948659.pdf
    • http://boystownchicagoseries.com/uploads/1/3/0/7/130776162/3341802.pdf
    • http://www.rx-fitnessmalaysia.com/uploads/1/3/0/5/130588858/minixanizi.pdf
    • http://roslecontractor.com/uploads/1/3/0/2/130287278/gazonizupixur.pdf
    • http://www.tirologistics.com/uploads/1/3/0/4/130483200/widupubilawe_sosanumi_rivuwikes_xojim.pdf
    • http://mail.integraled.org/uploads/1/3/0/5/130539004/lavik_suvodeb.pdf
    • http://natureiraqfoundation.org/uploads/1/3/0/7/130740617/717875db8.pdf
    • http://wenyingzhizunyule.br3h.com/uploads/1/3/0/6/130621020/eeb39.pdf
    • http://grooveshoprecords.com/uploads/1/3/0/3/130379307/3903039.pdf
    • http://lcofitness.com/uploads/1/3/0/7/130739349/tagivowas.pdf
    • http://stringsandsprings.com/uploads/1/3/0/4/130483178/4569558.pdf
    • http://www.agilbertphotography.com/uploads/1/3/0/5/130588518/guwijemuvopafilenu.pdf
    • http://mynicheblog.com/uploads/1/3/0/4/130476078/ponot.pdf
    • http://ventonconsulting.com/uploads/1/3/0/8/130813738/xupipab.pdf
    • http://out-the-back-door.com/uploads/1/3/0/4/130436313/b505c167e2.pdf
    • http://bgooddesignllc.com/uploads/1/3/0/6/130604488/fudalud.pdf
    • http://www.dresswithoutstress.help/uploads/1/3/0/6/130620470/4cfa45c520.pdf
    • http://webmail.katetrepagnier.com/uploads/1/3/0/8/130813033/rogusamuxubisibam.pdf
    • http://nursevisit.org/uploads/1/3/0/3/130313306/xovobivedufunititodo.pdf
    • http://edithbennett.com/uploads/1/3/0/7/130739204/6931876.pdf
    • http://www.beingmodish.shop/uploads/1/3/0/3/130379307/b375beeebeeed.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000762f.bin
ee7fdc4f58aacb5064292375cb2c653e627ee030ba2f66dedaf87120d1d1ecf3
pdf-font-stream PDF embedded font (sfnt) at offset 0x762F 7496 bytes
font_01_sfnt_off00009387.bin
915baeb1e29b1296448dc25187851e9706b77add1d29a836586dd6d4826066cd
pdf-font-stream PDF embedded font (sfnt) at offset 0x9387 2600 bytes