Malicious PDF — malware analysis report

Static analysis result for SHA-256 9672041b5b4e1d02…

MALICIOUS

PDF

37.2 KB Created: 2020-06-02 07:47:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 73692ae6c1c93e0e3a22ab95f97f4c66 SHA-1: f3e22e33140c0fb1ef14cc29118c04932e6a259c SHA-256: 9672041b5b4e1d02fcedfec517e37813b5b20a9911749e24b4a06061cca05448
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file exhibits characteristics of a link farm, with numerous external URLs embedded within its structure. The heuristic 'PDF_SEO_LINK_FARM' indicates a high volume of links, suggesting an attempt to manipulate search engine results or redirect users to potentially malicious content. While no scripts were extracted, the sheer number of external links, including the one at 'http://thetacticalfisherman.com/uploads/1/3/1/4/131438427/131438427.html#stellaris+tributary+or+vassal', points towards a malicious intent, likely for traffic redirection or phishing.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thetacticalfisherman.com/uploads/1/3/1/4/131438427/131438427.html#stellaris+tributary+or+vassal
    • http://highlandparkbaptistchurch.net/uploads/1/3/0/6/130604973/bejexabilosa_pitakererined_mitokadur_zawowolovekazex.pdf
    • http://theforceoftruthministries.com/uploads/1/3/0/8/130814157/vopevuz_pobil_namomazodepisoj_marizokule.pdf
    • http://oakbomb.com/uploads/1/3/0/9/130969079/8338976.pdf
    • http://dad.moisescastro.com/uploads/1/3/0/9/130969586/989dc48a.pdf
    • http://mail.gavenwilson.com/uploads/1/3/0/6/130604689/lijotikipadamedolori.pdf
    • http://ns1.4lightoflove.com/uploads/1/3/1/4/131406049/fbf699ea93d8b.pdf
    • http://thetacticalfisherman.com/uploads/1/3/1/4/131438427/terms.html
    • http://thetacticalfisherman.com/uploads/1/3/1/4/131438427/dmca.html
    • http://thetacticalfisherman.com/uploads/1/3/1/4/131438427/policy.html
    • https://teserofumuga.files.wordpress.com/2020/05/debixiten.pdf
    • https://gosigisor.files.wordpress.com/2020/05/72747689372.pdf
    • https://bamisenu.files.wordpress.com/2020/05/tevikaf.pdf
    • https://gidurum.files.wordpress.com/2020/05/xaluxomik.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066ed.bin
5d4fbc2d81ac054f671c21a5a098cc6416e14c8dc15e04ab23f285e52a508202
pdf-font-stream PDF embedded font (sfnt) at offset 0x66ED 10032 bytes