Malicious PDF — malware analysis report

Static analysis result for SHA-256 34d9f3acb59bf475…

MALICIOUS

PDF

43.3 KB Created: 2020-03-28 10:12:18 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5dfe77a5ad79ad30ecb41a12bb73fbb2 SHA-1: 65f6f5609fab4c4f0f668ba69f5eca21c8a4a416 SHA-256: 34d9f3acb59bf4750718e6a7198c2c338a396adc97399dc98e206b55ccdfff58
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or distribution mechanism. The embedded URL also points to an HTML file, further supporting the idea of directing users to external content. The primary purpose appears to be SEO manipulation or the distribution of further malicious payloads.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dominusdomus.com/uploads/1/3/1/0/131070291/131070291.html#healing+neen+discussion+questions
    • http://truelightessence.com/uploads/1/3/0/5/130539479/geludumunepes.pdf
    • http://somegirlonline.com/uploads/1/3/0/7/130775279/zezemi-vudubudupinuja.pdf
    • http://neuropsyhk.org/uploads/1/3/0/4/130436080/sozubesujesivax-nuzorewunij-davij.pdf
    • http://ford-roofing-low.com/uploads/1/3/0/7/130775294/begetuje.pdf
    • http://fiitted.net/uploads/1/3/0/9/130969211/4478689.pdf
    • http://jodyblackmore.com/uploads/1/3/0/2/130270826/aae9933.pdf
    • http://www.3strandedcord.com/uploads/1/3/0/4/130488087/b1b8b5a.pdf
    • http://asmarayoga.com/uploads/1/3/0/6/130621212/pupuzitojuwa.pdf
    • http://50klawn.net/uploads/1/3/0/3/130379105/puxunasi-tavumakur-tefujowaji-tebixuwone.pdf
    • http://diversyfy.com/uploads/1/3/1/1/131164497/ff7821b7f24e.pdf
    • http://careerpowertools.net/uploads/1/3/0/4/130478433/dipasedibegiwovu.pdf
    • http://colonialreinvestment.com/uploads/1/3/0/9/130969841/4f00eacb.pdf
    • http://jhdnhg.com/uploads/1/3/0/5/130588625/xavuniromaxa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000081f0.bin
d40e3565830452673ff129df9fb8b5dd80225e6f3638e75376296dd410b0e098
pdf-font-stream PDF embedded font (sfnt) at offset 0x81F0 7776 bytes