Malicious PDF — malware analysis report

Static analysis result for SHA-256 91f14c23001b261d…

MALICIOUS

PDF

62.6 KB Created: 2020-04-06 12:27:14 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 531e651568864bd4310ada20748532fc SHA-1: 804ca26f1907892c1cac319542063dc03fba8919 SHA-256: 91f14c23001b261db310f4a0d569683b7a29d31ddcc1daed1269f8de55ef30f0
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or distribution network. The document body, though heavily obfuscated, contains some of these URLs, indicating they are intentionally embedded. The primary purpose appears to be directing users to these external resources, which could host further malicious content or be used for SEO manipulation.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lavishcustomgifts.com/uploads/1/3/0/4/130476089/130476089.html#escudo+del+politecnico+nacional+del+callao
    • http://waterfordepiclocations.com/uploads/1/3/0/3/130323424/xiwebifa_genipigikubupew.pdf
    • http://timbrownvintagecamper.com/uploads/1/3/0/4/130483417/wunuwal.pdf
    • http://sayorale.org/uploads/1/3/0/4/130435633/merurame-bijilol-punapelifawa-vibafamonaj.pdf
    • http://sortng.com/uploads/1/3/0/7/130775267/1801420.pdf
    • http://nokia-review.com/uploads/1/3/0/5/130588998/3917b111.pdf
    • http://paulsfavoritestuff.com/uploads/1/3/0/7/130775276/piwox.pdf
    • http://globalvenue.org/uploads/1/3/0/6/130621818/f35ed0.pdf
    • http://gatorwedding.com/uploads/1/3/0/4/130491594/sapewufelupevo-mutonimefumofa-boruzebonigu.pdf
    • http://mrsquam.com/uploads/1/3/0/9/130969260/rozotaw.pdf
    • http://johnnypuckett.com/uploads/1/3/1/0/131070774/9af35.pdf
    • http://xgripbands.com/uploads/1/3/0/6/130639235/8429254.pdf
    • http://amethystretreatcenter.com/uploads/1/3/0/4/130475997/4210625.pdf
    • http://coloradopallet.com/uploads/1/3/0/7/130776230/danisixusirave-didoxim-motafesakutiwe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a7e9.bin
368b62b684eccc5a039576405130898a8b2b5f79d921b41bd5690f1843a85e71
pdf-font-stream PDF embedded font (sfnt) at offset 0xA7E9 11624 bytes
font_01_sfnt_off0000ccb5.bin
fe99f3cf5c22032b6a205105c04cca758faff213b63c29db5e8c872fe081e876
pdf-font-stream PDF embedded font (sfnt) at offset 0xCCB5 2680 bytes
font_02_sfnt_off0000d644.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0xD644 16036 bytes