Malicious PDF — malware analysis report

Static analysis result for SHA-256 49a7516c372a0603…

MALICIOUS

PDF

42.6 KB Created: 2020-03-12 12:49:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 7c989082f2ee263a76c54c414983d149 SHA-1: 79c8042866bb68165e672ea2329d725f9b6011a3 SHA-256: 49a7516c372a0603619177a256b9c5be1dd3ec52c3a41063b18d411dafe58a2d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which are numerically or generically named, suggesting a link farm or SEO spam operation. The document body text, while heavily obfuscated, contains references to 'Ap police si exam question paper' and includes URLs that further support this lure. The primary intent appears to be directing users to these external sites, potentially for phishing or to inflate search engine rankings.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://djbezza.com/uploads/1/3/1/0/131070220/131070220.html#ap+police+si+exam+question+paper
    • http://www.normantonmetalspinners.co.uk/uploads/1/3/0/7/130740173/kukunilidewineguxe.pdf
    • http://www.blackcirclerecords.net/uploads/1/3/0/5/130551176/7522825.pdf
    • http://basilandwoodie.com/uploads/1/3/0/6/130620391/nozujodakomafejudup.pdf
    • http://michaeleggerl.com/uploads/1/3/0/4/130490155/texotojumuw.pdf
    • http://mtbteam.baumcycles.com/uploads/1/3/0/7/130740375/jekolikez_leronez_taretimurewok_gufiwegele.pdf
    • http://mta-sts.zoojo.net/uploads/1/3/0/2/130271177/liroja.pdf
    • http://ntwstudioart.com/uploads/1/3/0/7/130776021/suroguloned.pdf
    • http://hostmaster.mi6app.com/uploads/1/3/0/6/130604752/rinolotugewi.pdf
    • http://propertypopups.com/uploads/1/3/0/5/130589285/4bab7e6c0c9dfbf.pdf
    • http://www.xn--80aqk7a6c.com/uploads/1/3/0/7/130775688/bejesibex.pdf
    • http://mail.goudenkerst.be/uploads/1/3/0/3/130323411/690c07bd55b5a7.pdf
    • http://maryg.me/uploads/1/3/0/9/130969408/jakamif.pdf
    • http://www.inflatablefunpark.nl/uploads/1/3/1/0/131070774/77fab6827cdcb.pdf
    • http://mta-sts.curiouscreatures.org/uploads/1/3/0/4/130483647/xorubugejoruluxodi.pdf
    • http://picturemachines.com/uploads/1/3/0/7/130739952/jejimesofuwat-bamidotafobu-rukisepiv.pdf
    • http://cadeirasonline.org/uploads/1/3/0/5/130588693/565253.pdf
    • http://www.harrisonburgrecklessdrivinglawyer.net/uploads/1/3/1/0/131071033/vipuvudokina-lawekadunazo-takarabo.pdf
    • http://meddin.space/uploads/1/3/0/5/130588332/pukatejoparutira.pdf
    • http://miamisammy.com/uploads/1/3/0/8/130814225/werotigu_xazopipabe_paxoluvilixa_bedixegarupe.pdf
    • http://www.asaircommunications.com/uploads/1/3/0/8/130813084/753bc3c1c27.pdf
    • http://terribletech.com/uploads/1/3/0/4/130435574/pidafoziximaj.pdf
    • http://atelierturner.fr/uploads/1/3/0/6/130604806/feb32f.pdf
    • http://mhrandlenovels.com/uploads/1/3/0/8/130814408/raxowonovi_xilusan.pdf
    • http://obieementor.com/uploads/1/3/0/8/130874620/23bf7.pdf
    • http://nirvanatails.net/uploads/1/3/0/6/130620407/gesojoti_sobagap.pdf
    • http://mhrandlenovels.com/uploads/1
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007c7f.bin
286763f466f10f9e90a8b25895bd3b8cb88846306f28572194f4672e0a3107ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C7F 8332 bytes