Malicious PDF — malware analysis report

Static analysis result for SHA-256 260722226311e021…

MALICIOUS

PDF

46.4 KB Created: 2020-03-23 01:45:51 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 69719b4f20563a562ab6212aaa74dd95 SHA-1: 2f727c523587f960f0451fc0996f9bbfb9609662 SHA-256: 260722226311e021cf8df9b0fddbfcf4b2fff9ded9ca69faeb88939d964a5307
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, a technique often used for SEO poisoning or to redirect users to malicious content. The heuristic 'PDF_SEO_LINK_FARM' specifically identifies this behavior, indicating the document's primary purpose is to serve as a gateway to numerous other PDF files hosted across various domains. No scripts were extracted, and the document body content is largely unreadable binary data, limiting further analysis of the specific lure.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hkcfoundationforparkinsons.org/uploads/1/3/0/7/130775563/130775563.html#inversa+de+cotangente+hiperbolica
    • http://www.vipgolfproamtour.co.uk/uploads/1/3/0/8/130813120/sazibopixujoridijut.pdf
    • http://alexmcmichael.com/uploads/1/3/0/6/130640028/zedugadu-konivanoxi-bogij-kasonu.pdf
    • http://jebmotley.com/uploads/1/3/0/2/130273573/texijezevowinepide.pdf
    • http://misbailes.com/uploads/1/3/0/7/130776888/4773018.pdf
    • http://heinzbarthel.com/uploads/1/3/1/0/131070767/9481511.pdf
    • http://easylivecontent.com/uploads/1/3/0/5/130588905/1816902.pdf
    • http://taoswellwoman.com/uploads/1/3/0/5/130588864/gevuwi.pdf
    • http://lushandlaughter.com/uploads/1/3/0/6/130621524/tafiwimukot-gakefojotazupas-setowixik-gazegevexoliben.pdf
    • http://processforgrowthconsulting.com/uploads/1/3/0/4/130489081/mojudusosekorom.pdf
    • http://netaganza2.netaganza.com/uploads/1/3/1/0/131070144/noluta-lubovi-jekezana.pdf
    • http://glorylandhouston.org/uploads/1/3/0/5/130551524/bodev_lisewis_xigak.pdf
    • http://verniceartmagazine.com/uploads/1/3/0/7/130776026/b15bab6e.pdf
    • http://rochecenter.org/uploads/1/3/0/7/130740164/vazim.pdf
    • http://divetogo.net/uploads/1/3/0/7/130738917/2090677.pdf
    • http://sdseco.com/uploads/1/3/0/4/130483566/612353.pdf
    • http://blueslimitedhk.com/uploads/1/3/0/9/130969437/991e11f8.pdf
    • http://mo-unlimited.com/uploads/1/3/0/6/130639910/7ab4aaeed.pdf
    • http://flava99.com/uploads/1/3/0/2/130289745/3234164.pdf
    • http://michaelwellsart.com/uploads/1/3/0/5/130588294/zatikogupuge-gabikiwudokof.pdf
    • http://www.livebetter-livehealthy.com/uploads/1/3/0/2/130287296/4772331.pdf
    • http://jokessofunny.com/uploads/1/3/0/6/130604497/442056.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069e6.bin
62bf70133831f98e46ab2a69c8192b0b06b2cbd76abbdfbf3df1583d695b75d9
pdf-font-stream PDF embedded font (sfnt) at offset 0x69E6 8960 bytes
font_01_sfnt_off00008ae4.bin
0ef1112e50e2a86488aadde4d8a477a3649c66578d8f2a84f2c6ad20bbddbbf8
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AE4 2732 bytes
font_02_sfnt_off00009491.bin
319f9c996375511bbe969d0b76506a2162f7d522988cd2631b41a5a1e417b94d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9491 16040 bytes