Malicious PDF — malware analysis report

Static analysis result for SHA-256 3382b5a27f4004c7…

MALICIOUS

PDF

30.1 KB Created: 2020-04-07 11:17:29 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 010c8c3979a0e8eb22b935e440af8d4e SHA-1: 34687f5f167103ab1ea959944126b656ffa72b78 SHA-256: 3382b5a27f4004c76a5c9142c7049c573444b4124c29be504f7292f486785c4a
70 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment

The PDF document contains a large number of external links, many of which point to other PDF files, suggesting a link farm or SEO poisoning tactic. One of the embedded URLs, 'http://nursingarmpillow.com/uploads/1/3/1/4/131437850/131437850.html#dell+color+laser+printer+1320c+driver+windows+10', is presented as a driver download, which is a common lure for malware delivery. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, reinforcing the malicious intent.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nursingarmpillow.com/uploads/1/3/1/4/131437850/131437850.html#dell+color+laser+printer+1320c+driver+windows+10
    • http://greentreetalent.com/uploads/1/3/0/6/130640229/vibijapozoki.pdf
    • http://cynthiaburgos.org/uploads/1/3/0/4/130483494/11472.pdf
    • http://teaguildofcanada.ca/uploads/1/3/0/6/130605324/a812ee15447.pdf
    • http://lovemycityoftrees.com/uploads/1/3/0/6/130605388/3580808.pdf
    • http://ciberfuneraria.com/uploads/1/3/1/4/131437549/7242029.pdf
    • http://realestatephotographertampabay.com/uploads/1/3/0/7/130775125/01850900bd6.pdf
    • http://dollhouseporcelain.com/uploads/1/3/0/6/130622013/eb6ee70f039.pdf
    • http://ignorantbehavior.com/uploads/1/3/0/6/130639852/vureza.pdf
    • http://offthebench.info/uploads/1/3/0/6/130621361/b933a7.pdf
    • http://ghspropertysolutions.com/uploads/1/3/0/4/130488565/piwefijikuru.pdf
    • http://hippiekrackgenetiks.com/uploads/1/3/0/5/130588377/xazuj_duruganojis_tifojafizefaw.pdf
    • http://dunedinrockchoir.org/uploads/1/3/0/5/130539107/9623504.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000050e8.bin
4964385f7d044b9602bc0a5be7c0cfa35b9d3274d37d11e8057734fc677cc06e
pdf-font-stream PDF embedded font (sfnt) at offset 0x50E8 6608 bytes