Malicious PDF — malware analysis report

Static analysis result for SHA-256 41599560ea82de69…

MALICIOUS

PDF

64.9 KB Created: 2020-03-25 04:14:29 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5f08267c9dd6aeb73dff58f5b12cf992 SHA-1: 096732387ac81c8a93b4a6a07bd1f32ebcda144c SHA-256: 41599560ea82de69b4cf80e5a7576c0531408b746cd31e6f18206c4a8c072dd0
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO manipulation tactic. The document body contains a seemingly innocuous title related to drawing, but the embedded links are the primary indicators of malicious intent. No scripts were extracted from this sample, limiting the ability to determine further payload delivery or execution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://infinitebuild.store/uploads/1/3/0/3/130313854/130313854.html#how+to+draw+kyubi+yo+kai+watch
    • http://laughable.news/uploads/1/3/0/7/130775076/8100239.pdf
    • http://kulalucampkenya.com/uploads/1/3/0/8/130814526/8160614.pdf
    • http://numbernineaesthetics.com/uploads/1/3/0/5/130543468/df470444b.pdf
    • http://acleancuttreeservicellc.com/uploads/1/3/0/5/130539370/zupudizomijexajoxal.pdf
    • http://benjaminsmithmusic.net/uploads/1/3/0/2/130289803/baec2a81de58e.pdf
    • http://tsabs.co.za/uploads/1/3/0/8/130813931/jasafazaxabase.pdf
    • http://texaswildernesstherapy.com/uploads/1/3/0/6/130603808/258c14.pdf
    • http://trialanalysiscorporation.com/uploads/1/3/0/8/130813846/5025014.pdf
    • http://herhealthstyle.com/uploads/1/3/0/5/130543272/jedunix-jejuralubasa-lirejimukoximol.pdf
    • http://stoguiracing.com/uploads/1/3/0/6/130621387/6189497.pdf
    • http://pivotpointsolutionsgroup.com/uploads/1/3/0/3/130313123/2126544.pdf
    • http://missfitmaroc.com/uploads/1/3/0/2/130272976/wokufutirewowodorevo.pdf
    • http://maddmagic.com/uploads/1/3/0/8/130813991/safinubu_pugulumik.pdf
    • http://mgmalehair.com/uploads/1/3/0/4/130476830/xosuf.pdf
    • http://toxique.org/uploads/1/3/0/4/130476912/3078973.pdf
    • http://myarkcenter.com/uploads/1/3/0/4/130488688/molewuge.pdf
    • http://mobilecraftbottlingcompany.com/uploads/1/3/0/6/130605065/vitilif-wikojek-lasaxilumemel-rafibibugawixi.pdf
    • http://nexgen-biosciences.com/uploads/1/3/0/2/130291699/17954b1a8aa63.pdf
    • http://myhempisbomb.com/uploads/1/3/0/6/130605438/lonitufelalokegazer.pdf
    • http://myarkcenter.com/uploads/1/3/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008762.bin
37d02b166cc16750e513baf02eb2c187a67e9262b809e28f0a10bb7c02d7f953
pdf-font-stream PDF embedded font (sfnt) at offset 0x8762 10148 bytes
font_01_sfnt_off0000ab5c.bin
c38f6f27d96c77abfc3d5f8b1e78fc38e22031d3d36b8d0e560a0d3133275ac2
pdf-font-stream PDF embedded font (sfnt) at offset 0xAB5C 12304 bytes
font_02_sfnt_off0000d2fb.bin
6644c704ad395c3c003427f3e693e8112d55946fcfd461d024716dbd7673f99a
pdf-font-stream PDF embedded font (sfnt) at offset 0xD2FB 2860 bytes
font_03_sfnt_off0000dce9.bin
892e9a0967cef8eb4a2b1c04ee373e8845e7252d1f8dd6fb9256ac587ab84b66
pdf-font-stream PDF embedded font (sfnt) at offset 0xDCE9 16356 bytes