Malicious PDF — malware analysis report

Static analysis result for SHA-256 40137265f281e277…

MALICIOUS

PDF

50.4 KB Created: 2020-03-26 01:59:28 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 7672e3663207961de93fa91ac3de08fd SHA-1: 0bc80be054889cb8b087085a1ccbc24655231f96 SHA-256: 40137265f281e2774ccbb499657f5431a304543b6cb092b18beea59e0bf50390
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, a technique often used to manipulate search engine results for specific keywords, such as 'descargar nero vision 10 full español'. The heuristic 'PDF_SEO_LINK_FARM' indicates that this PDF is part of a link farm designed to drive traffic to other sites. No scripts were extracted from this sample, and the document body is heavily obfuscated, limiting further analysis of its direct intent beyond link manipulation.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mrmacbiblebook2.com/uploads/1/3/0/6/130605263/130605263.html#descargar+nero+vision+10+full+espa%C3%B1ol
    • http://plancheewit.com/uploads/1/3/0/5/130550879/xuziwulapu.pdf
    • http://biblewordstudy.org/uploads/1/3/0/6/130604501/kuropevoguwufa.pdf
    • http://growthwithvictoria.com/uploads/1/3/0/8/130813504/2d6ff031.pdf
    • http://www.yogalife.com.au/uploads/1/3/0/4/130483351/0d9cdcfad4.pdf
    • http://www.lotusblvck.com/uploads/1/3/0/5/130589416/1e1980.pdf
    • http://christopherjarvis.co/uploads/1/3/0/5/130550983/kazipe.pdf
    • http://izzylaundry.com/uploads/1/3/0/5/130589088/9803239.pdf
    • http://mellysfashions.com/uploads/1/3/0/4/130436096/877288.pdf
    • http://courageblogs.com/uploads/1/3/0/7/130740087/bcbe4b0.pdf
    • http://linechoicemillwork.ca/uploads/1/3/0/4/130483527/banaka.pdf
    • http://tigerfoaminsulation.info/uploads/1/3/0/7/130739732/4549683.pdf
    • http://jimstack.net/uploads/1/3/0/6/130604815/tuwemoxuwebixokonuru.pdf
    • http://eyebrwsbdycare.com/uploads/1/3/0/3/130379332/4f98784d.pdf
    • http://challengetosociety.org/uploads/1/3/0/7/130775912/3547195.pdf
    • http://goringgapbusiness.net/uploads/1/3/0/5/130590383/226782.pdf
    • http://skipcoryell.com/uploads/1/3/0/5/130539446/6c78a7.pdf
    • http://handzfilbestcuisine.com/uploads/1/3/0/6/130621055/suloj.pdf
    • http://milwaukeetoireland.com/uploads/1/3/0/5/130550777/3626510.pdf
    • http://2924france.com/uploads/1/3/0/6/130620991/6324595.pdf
    • http://www.ryanodaypresents.com/uploads/1/3/0/6/130640114/lakazimuwi.pdf
    • http://brandonmcshaffrey.com/uploads/1/3/0/4/130436173/ranorosa.pdf
    • http://oplawncare.com/uploads/1/3/0/5/130544447/rerova.pdf
    • http://ballalae.com/uploads/1/3/0/7/130739968/59cfc28c9b851.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000077e5.bin
db5d1c12a967d4bd60a07073a3c0ccc8655b143c42a778913b5575cab4c36076
pdf-font-stream PDF embedded font (sfnt) at offset 0x77E5 8756 bytes
font_01_sfnt_off000097f6.bin
3f4932dd788eb800173c1fb49105834eca9ea54ea6a2e7a4d6dc37bcbca1f00b
pdf-font-stream PDF embedded font (sfnt) at offset 0x97F6 2792 bytes
font_02_sfnt_off0000a368.bin
5c8c152ee3201f81aae0fa5e0113f732667bbe18f087ca3c952201c589e2091b
pdf-font-stream PDF embedded font (sfnt) at offset 0xA368 16136 bytes