Malicious PDF — malware analysis report

Static analysis result for SHA-256 2eef2b2c7699b5b1…

MALICIOUS

PDF

42.9 KB Created: 2020-03-30 14:08:00 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 3ad728a7a57f83d6d94eb159828d8c27 SHA-1: 70ef0aeb856b85e178f3549f5faea7a3e5a696d0 SHA-256: 2eef2b2c7699b5b1af1bcd6dc0116cd570ffe67eecb56081da371c2e46ce1a61
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a large number of external links, many of which appear to be part of a link farm. This suggests a tactic to manipulate search engine results or to redirect users to potentially malicious content. No scripts were extracted, and the document body is heavily obfuscated, limiting further analysis of the specific lure. The primary attack pattern observed is the mass distribution of external URLs.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bailigongyulechengshoujiban.br3h.com/uploads/1/3/0/9/130969399/130969399.html#d+type+positive+edge+triggered+flip+flop+using+sr+latches
    • http://puntodeapoyo.es/uploads/1/3/0/5/130539584/kibutefeberobe-bulosaku-majupoxogemofut-vakekepadupefe.pdf
    • http://bloemisterijverwulgen.com/uploads/1/3/0/6/130640018/533e0.pdf
    • http://adjusteddevelopmentchiropractic.com/uploads/1/3/0/5/130550859/3cf53997d12.pdf
    • http://blythespiritsenterprises.com/uploads/1/3/0/5/130544954/debodijifavin_gotigukiwizubig_kewexug_xufonaniwiz.pdf
    • http://minds20.com/uploads/1/3/1/0/131070890/liritojobajaju-pazakavolobija-dobewokapoji.pdf
    • http://worldjamz.net/uploads/1/3/0/5/130551677/zesafazopebuxularati.pdf
    • http://nextwave.technology/uploads/1/3/0/8/130813372/3022753.pdf
    • http://itsrichardsim.com/uploads/1/3/0/9/130969708/8994516c8cdf.pdf
    • http://libraryjobsquad.org/uploads/1/3/0/7/130776148/bixek-luwivufusedekaw-kiwateves.pdf
    • http://shoesbyniki.com/uploads/1/3/0/2/130289019/2701943.pdf
    • http://rishi-holdings.com/uploads/1/3/0/4/130483690/6c0edf5a4.pdf
    • http://tylerhaycox.net/uploads/1/3/0/7/130740015/damumuzi-dutumev-dadebomajus.pdf
    • http://artsanimalsandawakenings.com/uploads/1/3/0/6/130603890/texixevugev_bolukezowudepaz.pdf
    • http://yumaeastlotowners.com/uploads/1/3/0/5/130539517/5253638.pdf
    • http://partybikebusiness.com/uploads/1/3/0/5/130545985/7954483.pdf
    • http://inspirationpublishings.com/uploads/1/3/0/7/130739686/106511.pdf
    • http://arkansasneuro.com/uploads/1/3/0/6/130639873/2677848.pdf
    • http://soulilluminations.com/uploads/1/3/1/0/131070798/josejumor-kuterata.pdf
    • http://pixelateduniverse.net/uploads/1/3/0/7/130775088/3065065.pdf
    • http://seyram-co.com/uploads/1/3/0/2/130289668/fojekizutizufibex.pdf
    • http://cheerage.com/uploads/1/3/0/2/130270762/9810810.pdf
    • http://nampaartgallery.com/uploads/1/3/0/6/130621388/5684863.pdf
    • http://famelessmom.com/uploads/1/3/0/5/130539437/meled.pdf
    • http://nampaartgallery.com/upl
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000743f.bin
2f337ec3149793a8d58975cefa3e935d3017cbaabc336c91f870fae09f5261fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x743F 7420 bytes
font_01_sfnt_off00009137.bin
37f5452301c093781c3d8370804b6f3f52cfdb8a2d7b415f708f676045b90d93
pdf-font-stream PDF embedded font (sfnt) at offset 0x9137 2732 bytes