Malicious PDF — malware analysis report

Static analysis result for SHA-256 58910d54a7251801…

MALICIOUS

PDF

53.3 KB Created: 2020-03-29 23:57:10 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 6272b8b32aaf611794167376b154d484 SHA-1: 2866bc5dd7eaaf6f72cd3668d73ffd8526e79cd7 SHA-256: 58910d54a725180152a1b62c42c564f5f9a96b3d1e174d5a2525ce7807bf9e8f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was generated by wkhtmltopdf and contains a significant number of embedded external links. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, suggesting a link farm or redirection scheme. The primary purpose appears to be to lure users to click on these links, which lead to other PDFs or HTML files hosted on various domains, likely for phishing or malware distribution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://74-123-72-53.mgwnet.com/uploads/1/3/0/8/130814345/130814345.html#momentos+en+vigas+empotradas
    • http://daa-quebec-projet.com/uploads/1/3/1/1/131164546/ff2c7011b7.pdf
    • http://shownosocks.com/uploads/1/3/0/3/130323581/kikukonim-papobo-jezalor.pdf
    • http://tattoosbypedro.net/uploads/1/3/0/6/130621691/bifawabejomef.pdf
    • http://masalafusion.net/uploads/1/3/0/2/130289270/defidoperuni-puvubovozamo-lolema-pafigesebaresiz.pdf
    • http://moyo-up.de/uploads/1/3/0/6/130620272/zurojin-fixeziduvuv-natisejezirebur-texudek.pdf
    • http://mesitoth.com/uploads/1/3/0/6/130604724/1767136.pdf
    • http://ghazalimd.com/uploads/1/3/0/6/130639489/1583976.pdf
    • http://wildwisdomplaytherapy.com/uploads/1/3/0/6/130620622/pimisukopobabo_nonevewuzomuma.pdf
    • http://www.elpasomovement.com/uploads/1/3/1/3/131379510/cb5def.pdf
    • http://ppy.life/uploads/1/3/0/8/130814014/ruwefo-nimulibizixiz-zijapogokorumu.pdf
    • http://geoleaktest.com/uploads/1/3/0/3/130323599/jokixovibam.pdf
    • http://jskmarket.com/uploads/1/3/0/3/130323430/2451939.pdf
    • http://fundaciontalitakumi.org/uploads/1/3/0/7/130776562/ec8e5864d2479f4.pdf
    • http://siptherapy.com/uploads/1/3/0/5/130590391/muveweluguzana-mopegenibol.pdf
    • http://katierosenberger.com/uploads/1/3/0/2/130291591/gofipep-metigeseze.pdf
    • http://alcidesrodriguez.com/uploads/1/3/0/6/130620669/e97ea977c3f2559.pdf
    • http://arany.ca/uploads/1/3/0/3/130379743/8369271.pdf
    • http://radicalartisticdesigns.com/uploads/1/3/0/4/130476469/fa52577a.pdf
    • http://1standrose.org/uploads/1/3/0/8/130813554/xefedef.pdf
    • http://loveawakeningwithin.com/uploads/1/3/0/7/130776174/4431174.pdf
    • http://2texasdips.com/uploads/1/3/0/6/130622061/xijipumanuwada.pdf
    • http://doctorluisfelipe.com/uploads/1/3/0/4/130478882/bazufozar.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009933.bin
d9c9458b2aae90a7c6c670dff840bbb40ecaa26a85f3bd3719ec386b2d0e8e48
pdf-font-stream PDF embedded font (sfnt) at offset 0x9933 8708 bytes
font_01_sfnt_off0000b927.bin
276d52c79cb6c4f26495c37a879d0fca90d05c177225f6eb54b2ffb208e5ef42
pdf-font-stream PDF embedded font (sfnt) at offset 0xB927 3432 bytes