Malicious PDF — malware analysis report

Static analysis result for SHA-256 371b68678408ec6b…

MALICIOUS

PDF

51.6 KB Created: 2020-04-08 03:13:52 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 8f779faba7224c66bf68366e74cb6860 SHA-1: 2c8508c105d7dde9ffd036ccefac655a222b21a8 SHA-256: 371b68678408ec6bfc953776927e0c32a6c2d2a0c63401c61b05f9aaf4d9f066
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF document contains a mass of external links, a common technique for SEO poisoning or phishing lures. The document body, though heavily obfuscated, contains text related to medical conditions and the tool used to generate the PDF. The primary intent appears to be directing users to potentially malicious or deceptive websites, as indicated by the numerous unknown-reputation URLs found within the document.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://slbconsultingservices.com/uploads/1/3/0/4/130488885/130488885.html#icd+10+code+for+malignant+neoplasm+of+right+kidney+except+renal+pelvis
    • http://logans-heroes.org/uploads/1/3/0/4/130436415/3bf76be.pdf
    • http://cfdaccounting.net/uploads/1/3/0/9/130969085/8ef8d5ad7c4ac5.pdf
    • http://atchisonair.com/uploads/1/3/0/6/130620515/bopozoxinumunal.pdf
    • http://mzocoill.com/uploads/1/3/0/7/130775627/nedibelakasamaz.pdf
    • http://pipersnaturalliving.com/uploads/1/3/0/5/130551338/2d2df4123d8d8a3.pdf
    • http://newmissnow.com/uploads/1/3/1/4/131408068/roxovewiw.pdf
    • http://frizzandfrockssociety.com/uploads/1/3/0/4/130475982/6300766.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a063.bin
ab123c124535482ff5781ed83c37e94091bed51be13f5e0583e19f4a91df9abf
pdf-font-stream PDF embedded font (sfnt) at offset 0xA063 8496 bytes