Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f89cf66f0610b52…

MALICIOUS

PDF

31.9 KB Created: 2020-05-30 22:08:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a68520bebf0dbce30c5f9bee40fe4e2 SHA-1: 7550c6d046b5b541b2b3de03e85390c73f6a3816 SHA-256: 7f89cf66f0610b52bea986bfee321fda07d88e50d6ebed304507821367f60284
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of external links, identified as a link farm, designed to redirect users to potentially malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, with the dominant host being 'music.tamss.biz'. The document body also contains a URL that appears to be part of this lure. The primary intent seems to be to drive traffic to these external sites for further exploitation or download.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://host190.carmichaelnl.com/uploads/1/3/0/3/130324248/130324248.html#female+agent+1.5+download
    • http://music.tamss.biz/uploads/1/3/0/7/130775116/fitagiriput.pdf
    • http://lasferramantas.com/uploads/1/3/1/3/131384226/rowajusiz_neloru.pdf
    • http://mytipsytaboo.com/uploads/1/3/1/4/131455283/mamava_wamegosoje.pdf
    • http://marculeroyal.com/uploads/1/3/0/7/130776446/daeb08a593946.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051e7.bin
e0c7f5fd4926e9d697cc42ad2f8297c7f5975c6881396f52965fc9ad3506114c
pdf-font-stream PDF embedded font (sfnt) at offset 0x51E7 10368 bytes