Malicious PDF — malware analysis report

Static analysis result for SHA-256 472a6a9f8ab1dd83…

MALICIOUS

PDF

62.8 KB Created: 2020-03-29 15:14:15 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 60c1d23835bb85704cd75aac0a39026e SHA-1: c489000f9dde6825c2971e20fd16c16993913f41 SHA-256: 472a6a9f8ab1dd83373e50947fedf2d64de2bb2ba3894fa3f23c4064a4f728a9
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to similarly structured URLs on different domains. The document body, though heavily obfuscated, contains a reference to 'caso clinico de neumonia pediatria pdf', suggesting a lure to disguise the malicious intent. The heuristic 'PDF_SEO_LINK_FARM' indicates a deliberate attempt to create a large number of links, likely for SEO manipulation or to host a variety of malicious payloads.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://host115.carmichaelnl.com/uploads/1/3/0/6/130639486/130639486.html#caso+clinico+de+neumonia+pediatria+pdf
    • http://pilgrimpowerplant.com/uploads/1/3/1/1/131164372/d6985fa79.pdf
    • http://isetfire.net/uploads/1/3/0/8/130813998/1793578.pdf
    • http://ladydigitalnomad.com/uploads/1/3/0/5/130551675/6220519.pdf
    • http://hand-brainlab.org/uploads/1/3/0/7/130775921/raxikasesenozav-levatefig-gopexurusufo-vopaja.pdf
    • http://red-poker.net/uploads/1/3/0/6/130621908/firulejavupojus.pdf
    • http://seconddaydust.com/uploads/1/3/0/5/130588529/sowipoti.pdf
    • http://gcourtneyphotography.com/uploads/1/3/0/7/130740563/04ac538112b.pdf
    • http://dmitrenko.org/uploads/1/3/0/2/130270893/567ff838.pdf
    • http://limosuvcom.org/uploads/1/3/0/4/130476565/287a9.pdf
    • http://liberia2016.com/uploads/1/3/1/1/131163737/1384bff206b.pdf
    • http://premodsystems.com/uploads/1/3/0/8/130874381/2278483.pdf
    • http://setpe.org/uploads/1/3/0/6/130604458/2212217.pdf
    • http://connallychristianacademy.org/uploads/1/3/0/2/130289177/2746777.pdf
    • http://sansouciart.com/uploads/1/3/0/6/130639138/tosazegojabizeg-jujezunelek-wewabof.pdf
    • http://poeticspace.net/uploads/1/3/0/6/130604279/4970cec1072.pdf
    • http://projectrohingya.com/uploads/1/3/0/5/130540359/842c78bbc.pdf
    • http://groovetw.com/uploads/1/3/0/4/130476733/vuzaxasibipirafos.pdf
    • http://kristienienabercounseling.com/uploads/1/3/0/3/130379135/e68acb83ceae.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c225.bin
7d0e4f26927737c593ed7efda103a1107150fe3ac8ddbcafaf6ee6c0af50a0b0
pdf-font-stream PDF embedded font (sfnt) at offset 0xC225 1588 bytes
font_01_sfnt_off0000c9da.bin
1e64f95baa3d64b2fb00d76f1afba088d4f97c5c12bb9d41a0e4d9245f2ee854
pdf-font-stream PDF embedded font (sfnt) at offset 0xC9DA 9408 bytes