Malicious PDF — malware analysis report

Static analysis result for SHA-256 4156ee3e1849c21f…

MALICIOUS

PDF

38.2 KB Created: 2020-06-06 08:20:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 68520bec806436fff532cda1083b7c3b SHA-1: 029cd1c9ec0ee932a8414ff25776ec6ff9f6f2c0 SHA-256: 4156ee3e1849c21f0fbcbfd4b13e9a31c220776468d55e3147374f6f4d982de9
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which point to SEO-optimized PDF files on various domains. This pattern is indicative of a link farm designed to attract traffic or distribute further malicious content. The primary heuristic identified a "PDF_SEO_LINK_FARM" which strongly suggests this malicious intent. The embedded document body text, while partially corrupted, contains a URL that aligns with the observed link farm structure.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ff.undesirable.us/uploads/1/3/0/4/130435694/130435694.html#coil+sar%25C4%25B1m+tablosu
    • http://hoskindesigns.com/uploads/1/3/0/4/130483368/dotitinomow.pdf
    • http://aomen21dian.br3h.com/uploads/1/3/1/4/131453817/gopew_dixopobiz.pdf
    • http://okomomodesign.com/uploads/1/3/0/5/130551270/4694390a.pdf
    • http://consentstories.com/uploads/1/3/0/8/130814088/9139025.pdf
    • http://saranaponline.org/uploads/1/3/1/4/131483253/3ee8dae872.pdf
    • http://mta-sts.mail.ansjewellens.be/uploads/1/3/0/7/130775456/tefosovurowe_rewafobefizunu_tevuramid_tezebizivubov.pdf
    • http://lidhjashqiptare.org/uploads/1/3/0/7/130739926/9487111.pdf
    • http://beautifulsoulspa.com/uploads/1/3/0/4/130488304/vilefuterima.pdf
    • http://lipsynthia.com/uploads/1/3/0/7/130775260/gedozaduwem.pdf
    • http://bigisle.sustainhawaii.org/uploads/1/3/1/6/131606416/b12898a743cfb79.pdf
    • http://ff.undesirable.us/uploads/1/3/0/4/130435694/terms.html
    • http://ff.undesirable.us/uploads/1/3/0/4/130435694/dmca.html
    • http://ff.undesirable.us/uploads/1/3/0/4/130435694/policy.html
    • http://bigisle.sustainhawaii.org/uploads/1/3/1/6/131606416/b12898a743cfb79.p
    • https://kuzelelete.files.wordpress.com/2020/06/35633724369.pdf
    • https://fawibulakav.files.wordpress.com/2020/06/wedojoduzojajavut.pdf
    • https://runokuxuzeni.files.wordpress.com/2020/06/82989493943.pdf
    • https://pekazad879287334.files.wordpress.com/2020/06/rewuverafolawelunud.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000674b.bin
9ce28a6decaec3f192e2affb37a91d691632ffd299e56c646a7bc531d2cc12e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x674B 11308 bytes