Malicious PDF — malware analysis report

Static analysis result for SHA-256 a26a5404b384b92f…

MALICIOUS

PDF

43.2 KB Created: 2020-04-06 13:32:37 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 96a65535c165111b8179cdec529cbbb8 SHA-1: e888bbf9df12df6fce9c0f7ff7c80af240d13c51 SHA-256: a26a5404b384b92ffb648129dc2a8078bae20f9975728f1897a80ef5b373fb1e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or redirection scheme. The primary purpose appears to be directing users to these external resources, potentially for SEO manipulation or to host malicious content. No scripts were extracted, limiting further analysis of direct payload delivery.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://timeframingconsulting.com/uploads/1/3/0/6/130639960/130639960.html#250+mph+to+km%2Fh
    • http://agrarischehoofdstad.com/uploads/1/3/0/7/130776781/buvebof_boramuxateb.pdf
    • http://felicityturner.net/uploads/1/3/0/6/130604532/somen_sijuta_disiromofanu.pdf
    • http://ilovemoostudios.com/uploads/1/3/0/5/130546294/09b3734981.pdf
    • http://laclinicadellavoro.com/uploads/1/3/1/0/131071286/5249716.pdf
    • http://willmonkslighting.com/uploads/1/3/0/5/130588220/zajananupejosap.pdf
    • http://myprintpad.com/uploads/1/3/0/2/130289332/4fa1fd.pdf
    • http://rauldelacruzlinacero.com/uploads/1/3/0/5/130551423/pidozadimigozaz.pdf
    • http://stringlineconstruction.org/uploads/1/3/0/4/130435826/vuzarajamagasapok.pdf
    • http://donnasdancefund.com/uploads/1/3/0/8/130874332/digogugosurupanixa.pdf
    • http://gifted-richmond.com/uploads/1/3/0/5/130589115/acb3f0e21d68.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006a7e.bin
8eb40dc7c96e2805814278c9a030a4379397e6a8a01352b39d8dfad5bb5f20fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A7E 8628 bytes
font_01_sfnt_off00008a00.bin
6d1d4133b71073f8a3da00521dff60815bab0c5011baf7c5950313a09bbf8023
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A00 16344 bytes