Malicious PDF — malware analysis report

Static analysis result for SHA-256 2cd1f959c2ffe769…

MALICIOUS

PDF

113.5 KB Created: 2020-04-01 14:32:04 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 492a376f187f9f1ea13a42053c3e3db8 SHA-1: 2a063bac1ad0256bf8b55b6f1030a8ce0d206be2 SHA-256: 2cd1f959c2ffe76934e7abf1a3354e3d970081132e8fe317e0b5a4d0bb88e0d5
62 Risk Score

Malware Insights

MITRE ATT&CK
T1598 Gather Victim Identity Information T1204 User Execution

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or SEO manipulation tactic. The embedded URL also points to an external HTML resource. No scripts were extracted from this sample, limiting the ability to determine further malicious intent beyond the link distribution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vishuddi.net/uploads/1/3/0/8/130874077/130874077.html#army+blue+2+report+example
    • http://themalatang.com/uploads/1/3/0/8/130874223/bepano.pdf
    • http://johanlagerlof.net/uploads/1/3/0/2/130289201/lozudewegopitef.pdf
    • http://ellenkochyoga.com/uploads/1/3/0/7/130775768/saxemidojom.pdf
    • http://plussizeweddingdressconnecticut.com/uploads/1/3/0/9/130969481/vesodamelerimevax.pdf
    • http://paradigmfactory.com/uploads/1/3/0/4/130483973/powisurexalat-vibowukenajes.pdf
    • http://adaccountingservices.com/uploads/1/3/0/4/130476012/divulixupebus-bazag.pdf
    • http://lightonmyfeet.com/uploads/1/3/1/4/131407247/9426912.pdf
    • http://bhpcd.org/uploads/1/3/1/3/131378918/nodapurana-luzofot-topug-lufepuselez.pdf
    • http://practice-peaceyoga.com/uploads/1/3/0/6/130620494/696ef554b51.pdf
    • http://myleokingspage.com/uploads/1/3/0/6/130621909/jolinatog.pdf
    • http://rosepedalclothing.store/uploads/1/3/0/7/130739457/4412512.pdf
    • http://karlazehren.com/uploads/1/3/1/0/131069759/1057086.pdf
    • http://thepinkgatoshop.com/uploads/1/3/0/6/130639516/7a747.pdf
    • http://adisera.com/uploads/1/3/0/3/130380002/kuxof.pdf
    • http://mta-sts.livingnativity.org/uploads/1/3/0/9/130969452/rijavofetimilosak.pdf
    • http://eaglestonegrp.com/uploads/1/3/0/5/130551856/7776060.pdf
    • http://rachelleffel.com/uploads/1/3/0/5/130545278/a1c1337f06.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000199b1.bin
1e46d96197767cdaae1799e9e639ac60edc9794d0c88af71787660ce28291667
pdf-font-stream PDF embedded font (sfnt) at offset 0x199B1 7772 bytes