Malicious PDF — malware analysis report

Static analysis result for SHA-256 7dbd9e8a58ab93da…

MALICIOUS

PDF

38.1 KB Created: 2020-05-16 22:30:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 90c79a85c36ea5fa67ea9e84e731dd94 SHA-1: 3011e2fc8ac7c2a641f47b6e414e210730ede469 SHA-256: 7dbd9e8a58ab93da957c048c310c885c52c324751b160d14dafdce8a0ce621e4
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or SEO manipulation tactic. The document body contains a title related to geode crystals and the authoring application information, but the primary malicious activity is the distribution of these numerous external links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://onkoyoga.com/uploads/1/3/1/4/131407083/131407083.html#geode+crystal+identification+guide
    • http://sejour-linguistique-australie.ch/uploads/1/3/0/5/130590678/9539896.pdf
    • http://arquitetandoartes.com/uploads/1/3/0/6/130620843/mujasa.pdf
    • http://mizzbombshell.com/uploads/1/3/0/2/130289541/nixabuj.pdf
    • http://mysbeauty.com/uploads/1/3/0/4/130488169/3084007.pdf
    • http://smcconsulting.fr/uploads/1/3/1/4/131409926/voxij-memoma.pdf
    • http://tamiymhealthandfitness.com/uploads/1/3/1/8/131857144/2342533.pdf
    • http://eurobonus.lt/uploads/1/3/0/5/130589124/kikejabe-vidivojefoji-bizis-gepoda.pdf
    • http://piercelegislativeforum.com/uploads/1/3/0/5/130544072/2548089.pdf
    • http://kimjarvis.net/uploads/1/3/0/6/130620555/31a9594.pdf
    • http://eibbedpadilla.com/uploads/1/3/1/0/131070314/biwituguwuwebimes.pdf
    • http://dironrutty.com/uploads/1/3/0/7/130739068/9e8f6.pdf
    • http://portagejiu-jitsu.net/uploads/1/3/0/6/130640164/jenewabasusen.pdf
    • http://gettingscripted.com/uploads/1/3/1/4/131406321/ganisuwaguxazubiba.pdf
    • http://ma-logan.com/uploads/1/3/0/8/130873976/xaxonijuvaxinafiduxo.pdf
    • http://schmaltzcreative.shop/uploads/1/3/0/6/130605490/6d702596.pdf
    • http://addictivedecadantmusthaves.com/uploads/1/3/0/5/130588531/xikegoda_fudovesu_gobovux.pdf
    • http://anthony-hart.com/uploads/1/3/0/7/130775822/jitupaxonedisim-taxinuxovus-pigirorusug-kerer.pdf
    • http://julietew.com/uploads/1/3/0/8/130874289/4670114.pdf
    • http://sandrahaus.com/uploads/1/3/0/7/130739629/7759067.pdf
    • http://helse-velvare.no/uploads/1/3/0/5/130551090/4340962.pdf
    • http://consecogroup.net/uploads/1/3/0/3/130323161/foverod.pdf
    • http://9f60hmh100.com/uploads/1/3/0/7/130775259/venemozavok.pdf
    • http://vaganture.com/uploads/1/3/0/7/130739452/mulokurupapiboku.pdf
    • http://rosandcompany.com/uploads/1/3/1/3/131398358/fedul.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006970.bin
481131f69b75bf474d4a60348e2c48415c6dbacd35a6e24c4ad9e9211ad5a6b9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6970 10276 bytes