Malicious PDF — malware analysis report

Static analysis result for SHA-256 3936bc7e740cc6d9…

MALICIOUS

PDF

55.0 KB Created: 2020-03-12 01:51:25 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5cc01cbe51a6f5a1e8a265d9212b74fd SHA-1: d2df7bd23dc2a24255a39eac66095c4412aa7cbb SHA-256: 3936bc7e740cc6d9912480a644ca9dff40d2d1c9d7e3539e8c2e7501d24d9864
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or redirection mechanism. The embedded URLs are likely used to lure users into clicking them, potentially leading to malicious content or further exploitation. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.gemyoga.org/uploads/1/3/0/3/130313253/130313253.html#a+4+bit+parallel+adder+may+be+constructed+by
    • http://www.littlebitofheat.com/uploads/1/3/0/5/130551229/bfd5a539897.pdf
    • http://dematic-university.com/uploads/1/3/0/6/130604907/c3fa0aab01.pdf
    • http://alpine-hiking.co.uk/uploads/1/3/0/5/130551132/6a470c03e813fd.pdf
    • http://autopowercar.com/uploads/1/3/0/2/130288421/5eecf1f9b8.pdf
    • http://summitdentalaccounting.mobi/uploads/1/3/0/6/130620973/sufuku_nivegemapere_zosip_kekuvi.pdf
    • http://mrssnydersclass.com/uploads/1/3/0/2/130289466/bobewiko.pdf
    • http://landofosllc.net/uploads/1/3/0/4/130435670/sotow-jerotov-wolajoser-zokugoxiwig.pdf
    • http://www.thebainbridgefarmersmarket.com/uploads/1/3/0/5/130544131/govuvibalul.pdf
    • http://reboundat.com/uploads/1/3/0/4/130435717/jalidupave-ramar.pdf
    • http://ilyasustun.info/uploads/1/3/0/6/130604508/1625338.pdf
    • http://allegro.co.nz/uploads/1/3/0/3/130313072/mizimuxe.pdf
    • http://mygcstm.com/uploads/1/3/0/5/130550834/9622682.pdf
    • http://2018.otty-jc.jp/uploads/1/3/0/4/130435590/3127059.pdf
    • http://www.charleylama.com/uploads/1/3/0/5/130538859/wujeziz-figelixavutiren-soxazevag.pdf
    • http://www.rfslaw.com/uploads/1/3/0/2/130287283/goliderafuludalabe.pdf
    • http://clubmegamixradio.net/uploads/1/3/0/5/130589309/remubuzizitesosa.pdf
    • http://occseagles.org/uploads/1/3/0/7/130775458/72ee8d099b27.pdf
    • http://caraboo.co/uploads/1/3/0/8/130873941/borejukurusarabidaze.pdf
    • http://chavezinsagency.com/uploads/1/3/0/5/130551179/rapeseferan.pdf
    • http://coolshoes.biz/uploads/1/3/0/3/130312913/madewudutiwopelovabo.pdf
    • http://hcskcmo.com/uploads/1/3/0/8/130814209/gurufawume.pdf
    • http://neolithia.com/uploads/1/3/0/6/130622047/sojerigawi-nonepubijiw-gafofapeboka-molalom.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008c42.bin
2ec1afe4a4c870c7c852b8cc2ee4aeed8593a6dfc10bf92e6c6d80f6a9a7ea7a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C42 8848 bytes
font_01_sfnt_off0000adfd.bin
63f5e27ee3d24cc00d413e59c301cc73ab377383609796993547673f2bea898c
pdf-font-stream PDF embedded font (sfnt) at offset 0xADFD 2600 bytes
font_02_sfnt_off0000b729.bin
87199be0e1dac87daae45aa4c87df7ee137f6712c5f0fe75f8da48029b6296d1
pdf-font-stream PDF embedded font (sfnt) at offset 0xB729 16300 bytes