Malicious PDF — malware analysis report

Static analysis result for SHA-256 91ef9f814678f897…

MALICIOUS

PDF

46.1 KB Created: 2020-05-23 20:52:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 41fff085da8796e1f8fd76db2bc51e8b SHA-1: ca765981074f071046c92eca1b5271a5b1496a15 SHA-256: 91ef9f814678f8978ab6d8be61097960bbbcc640708c80a18f2c8c3d77b1e842
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, disguised as a fitness guide. The document body text is heavily obfuscated but contains references to the 'Bodyboss ultimate body fitness guide' and the authoring application 'wkhtmltopdf'. The primary attack pattern involves redirecting users to numerous external URLs, likely for SEO spam or to host malicious content.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://themagnoliasestate.com/uploads/1/3/0/2/130289508/130289508.html#bodyboss+ultimate+body+fitness+guide
    • http://dalmaresproduce.com/uploads/1/3/1/4/131438002/8418e.pdf
    • http://muadmusicfever.com/uploads/1/3/0/9/130969621/muxusojulo.pdf
    • http://twbmotors.com/uploads/1/3/0/7/130738998/57fd7d9f1a8b6.pdf
    • http://heartofyogarva.com/uploads/1/3/0/5/130550724/sojojupel.pdf
    • http://engagementguyconsulting.com/uploads/1/3/0/9/130969738/d03c9d2bad5a.pdf
    • http://healimmune.com/uploads/1/3/0/2/130272443/6ad79a96440a.pdf
    • http://msdtesting.com/uploads/1/3/0/6/130620464/tabafekowo.pdf
    • http://thesavvygirlguide.com/uploads/1/3/1/4/131453387/zufumizeloponelo.pdf
    • http://kegakoblinds.com/uploads/1/3/0/4/130476469/xixepoboziko_kazonoxam.pdf
    • http://5divagirls.com/uploads/1/3/0/6/130621831/67d1e4f.pdf
    • http://rontticat.com/uploads/1/3/1/6/131637219/f93c1bf.pdf
    • http://achoir.org/uploads/1/3/0/8/130814559/rivigilalizuterozudu.pdf
    • http://surberlaw.org/uploads/1/3/0/7/130775922/a20ec.pdf
    • http://varmaccounting.com/uploads/1/3/1/6/131637247/noxiso_kolew_tonad.pdf
    • http://memorystones.ca/uploads/1/3/0/5/130543087/a3272.pdf
    • http://wecanbemindful.com/uploads/1/3/0/4/130489054/kufujosuzanani_depijipab_dekulew.pdf
    • http://thegivenessproject.org/uploads/1/3/0/5/130550785/2da86820.pdf
    • http://my-lazio.com/uploads/1/3/1/4/131482850/sinomiredu_dotuxino_nidugob_zelum.pdf
    • http://nontique.com/uploads/1/3/0/9/130969446/b839e4a4efee28d.pdf
    • http://kalilabdullah.com/uploads/1/3/0/4/130483244/fugonenimov.pdf
    • http://successfulbusinessstrategies.com/uploads/1/3/0/5/130546937/kalowut.pdf
    • http://sprinklesweets.com/uploads/1/3/0/6/130621393/6086592.pdf
    • http://reneedumarr.com/uploads/1/3/0/7/130739871/kekotudoko_bonubaneto_vunamapa_repej.pdf
    • http://maxluxeminklashes.com/uploads/1/3/0/3/130313504/degobugadulojil_jemeboluf_depur_zuxajebos.pdf
    • http://bestak47.com/uploads/1/3/0/5/130544072/kibaboviz_pilipubol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007658.bin
d8516b967b6be069a2f17b596fd094a86b8dac13c0ce90cebf75e389cbe0895a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7658 5012 bytes
font_01_sfnt_off00008402.bin
fd1e26babd78f0341d38e527968144023f5191f1f0ddbc43cca3297af77b88df
pdf-font-stream PDF embedded font (sfnt) at offset 0x8402 11604 bytes