Malicious PDF — malware analysis report

Static analysis result for SHA-256 841f708e7a1c1d8b…

MALICIOUS

PDF

67.1 KB Created: 2020-03-13 01:56:47 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: fe5c8c5165c1213a77e1c2964b171c6a SHA-1: ead92b6746d48286e93048bb204895b69b055bed SHA-256: 841f708e7a1c1d8bcae7ce9693290b212ca5f756e28c23861ec93b523632ea46
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which point to other PDFs hosted on domains designed to appear as legitimate content providers. This pattern is indicative of a link farm used for SEO manipulation, likely to host malicious content or phishing pages. The document body itself is heavily obfuscated and contains embedded URLs that further support this attack pattern.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hyperion-ai.com/uploads/1/3/0/7/130739240/130739240.html#estimation+of+covariance+matrix+multivariate+normal
    • http://thceasoningsspaandhome.com/uploads/1/3/0/3/130313082/norawonovo.pdf
    • http://www.taotheologyandculture.org/uploads/1/3/0/4/130483875/napitolezidu.pdf
    • http://celticchurchmaui.org/uploads/1/3/0/4/130435746/1739639.pdf
    • http://mountainvilleumc.com/uploads/1/3/0/3/130323967/3091611.pdf
    • http://hostmaster.dinahparums.org/uploads/1/3/0/5/130543059/7766ec9a0.pdf
    • http://www.mediation-misbruik.nl/uploads/1/3/0/6/130621330/gasefosanawi-sulav-rafevoxagabi.pdf
    • http://peoriamfg.com/uploads/1/3/0/5/130588499/2589908.pdf
    • http://www.ecommerce102.org/uploads/1/3/0/8/130814106/leketekubuxiwogo.pdf
    • http://youthtech.de/uploads/1/3/0/6/130604321/guwomesidisabodekoz.pdf
    • http://mail.impresspartyrentals.com/uploads/1/3/0/6/130604198/9f761029.pdf
    • http://www.newglasgowmassage.ca/uploads/1/3/0/5/130538862/vefoxane.pdf
    • http://mta-sts.mail.hydeparksuzuki.org/uploads/1/3/0/5/130545885/45c4c66dddb370.pdf
    • http://plr.group/uploads/1/3/0/5/130550981/b84eef176.pdf
    • http://abcofxxx.com/uploads/1/3/0/4/130476885/nejil.pdf
    • http://www.causewecan123.org/uploads/1/3/0/5/130550970/e88224d252ed7.pdf
    • http://the5statesofteamsuccess.com/uploads/1/3/0/5/130551338/a2fc42b7c282c31.pdf
    • http://www.duxburygb.co.uk/uploads/1/3/0/5/130588461/gemifaxemekujiloruka.pdf
    • http://cpanel.grandriverblues.org/uploads/1/3/0/7/130740490/tuguteronomo.pdf
    • http://www.coreconsulting.com/uploads/1/3/0/4/130494478/nunuve-vuxader-xurakulo-wakobufu.pdf
    • http://animalmatters.com.au/uploads/1/3/0/5/130539227/9685939.pdf
    • http://rifugiovallegrande.online/uploads/1/3/0/4/130488476/nibijobanagidupigu.pdf
    • http://nidinidi.com/uploads/1/3/0/3/130323151/pamewimor-duluxexajukag-wexanixovun.pdf
    • http://hostmaster.girltowoman.com.au/uploads/1/3/0/5/130551222/tunelusopugaxovumoke.pdf
    • http://rifugiovallegrande.online/uploads/1/3/0/4/130488476/nibijoba
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b72a.bin
6f19e8bf54e98764b5e8d58fc18bf51ffbabc65fef420a47785e8e4f560e4cf9
pdf-font-stream PDF embedded font (sfnt) at offset 0xB72A 9140 bytes
font_01_sfnt_off0000da04.bin
49f8c933ea0a0e57805b597ddafa49cd536bd4421f1a3c556adf91bd043eb7e3
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA04 3588 bytes
font_02_sfnt_off0000e6b9.bin
e31b2f7a9849f515ed03460fede15f4796f0f5e049bf9898e594a64095fd747f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6B9 16484 bytes