Malicious PDF — malware analysis report

Static analysis result for SHA-256 45f2b662fb27dd18…

MALICIOUS

PDF

44.0 KB Created: 2020-03-28 08:45:43 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5096eab77d5e96b1d7a8d50c9a52e5a1 SHA-1: 53df885a40d2f19bd567fe24d74d47040b13b246 SHA-256: 45f2b662fb27dd1820aee15ea4597ebd5b828ccf8a52a1369b602b6953acda50
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded external links, identified as a link farm. This technique is often used to distribute malicious content or to artificially inflate search engine rankings for malicious sites. No scripts were extracted, and the document body is heavily obfuscated, making it difficult to determine the exact nature of the linked content. The primary attack pattern observed is the distribution of a large number of URLs.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://acehomestay.com/uploads/1/3/1/0/131070619/131070619.html#movimiento+parabolico+teoria+pdf
    • http://ashleighvaillancourt-winebrenner.com/uploads/1/3/0/5/130543488/6865915.pdf
    • http://usatfregistration.com/uploads/1/3/0/2/130271143/fanuguragiwag.pdf
    • http://mail.adishalit.com/uploads/1/3/0/4/130490056/fazafipezujisivapu.pdf
    • http://rebirthhypnosis.com/uploads/1/3/0/7/130775129/109e5c681c63.pdf
    • http://charmaines.net/uploads/1/3/0/3/130323817/zatarasewazifujufew.pdf
    • http://www.csdesigns.com/uploads/1/3/0/6/130620767/8410640.pdf
    • http://chicagoentrepreneuher.com/uploads/1/3/0/7/130775229/2016277.pdf
    • http://freedomwizards.com/uploads/1/3/0/5/130539074/3919580.pdf
    • http://www.willembphotography.com/uploads/1/3/0/5/130542940/tusimobobuwak.pdf
    • http://addaihealthedu.net/uploads/1/3/0/7/130776043/9226798.pdf
    • http://aveh.com/uploads/1/3/0/6/130604576/4952014.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007786.bin
79c51b6c097e6ce33b704659938da31a73dfeb935c07027548b04849e7cbf0df
pdf-font-stream PDF embedded font (sfnt) at offset 0x7786 9172 bytes
font_01_sfnt_off00009907.bin
11eff0542ee112a7a4f3d5fa86892f13f7f7c80edb17354215cea33bb7714487
pdf-font-stream PDF embedded font (sfnt) at offset 0x9907 2768 bytes