Malicious PDF — malware analysis report

Static analysis result for SHA-256 29b8053e2306eec4…

MALICIOUS

PDF

53.4 KB Created: 2020-03-27 06:27:47 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 7162da220f59cad6a2e82d702b6f1ea6 SHA-1: 8f2b8125d64fbdcd89a6fb89a4187b2c7711b9e4 SHA-256: 29b8053e2306eec4bd820554e03f49458eb3896ec58f19228f95c5b76dd4a0a6
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document exhibits characteristics of a link farm, embedding a large number of external URLs. The primary heuristic identified a mass external PDF link farm with 28 links, predominantly hosted on www.slautoworx.com. While no scripts were extracted, the sheer volume of outbound links suggests an attempt to manipulate search engine results or redirect users to potentially malicious sites. The document body contains garbled text and metadata, offering no further clues to the specific intent beyond the link farm.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pearlseattle.com/uploads/1/3/0/4/130435784/130435784.html#elementos+tabla+periodica+con+d
    • http://www.slautoworx.com/uploads/1/3/0/8/130874258/lebuforof-lunegifukuwo.pdf
    • http://brianpatrickwilliams.com/uploads/1/3/0/6/130605299/bbad66.pdf
    • http://jillunikel.net/uploads/1/3/0/2/130270914/3ca8c.pdf
    • http://consercoinc.com/uploads/1/3/0/6/130622036/sopuduw.pdf
    • http://excelaircare.com/uploads/1/3/0/6/130604739/wipikumetesaga_pafafikemu.pdf
    • http://joinhamlet.com/uploads/1/3/0/5/130540937/590466.pdf
    • http://jimbentley.net/uploads/1/3/0/9/130969090/tevunubijaduxe_zojozilesavoj_negomesezogazaj_gigiwu.pdf
    • http://graceandainc.com/uploads/1/3/0/8/130873971/tefot.pdf
    • http://oberhofferfamily.com/uploads/1/3/0/5/130550657/1f1b029d7.pdf
    • http://redrobedrum.com/uploads/1/3/0/4/130483937/44735.pdf
    • http://topdressinglawnsandgardens.com/uploads/1/3/0/6/130639785/fiziwo_walubo_teweborudilo.pdf
    • http://kidinterviews.com/uploads/1/3/0/2/130289480/a4e702feb4739c.pdf
    • http://www.test.saroswave.com/uploads/1/3/0/4/130476078/gozokenevoxutasixon.pdf
    • http://pompstirenorfolk.com/uploads/1/3/0/6/130621683/4081252.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a32c.bin
2448e9718ae409aee125d7517742757916459d5c5749852915d1cb6650a20f01
pdf-font-stream PDF embedded font (sfnt) at offset 0xA32C 9904 bytes