Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7f9934b1b6b0cbc…

MALICIOUS

PDF

44.2 KB Created: 2020-03-29 14:41:50 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 48a21f10e906835c6435bf450bf610b6 SHA-1: 80a254234c82813a503013ebef360b542b4f170e SHA-256: a7f9934b1b6b0cbc37767a1d71bfedba3b9c597ba7afe3c1728660df70884d13
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a significant number of external links, indicating a link farm strategy. The primary heuristic firing, PDF_SEO_LINK_FARM, confirms this behavior, suggesting the document's purpose is to direct users to a large collection of other PDFs hosted on various domains. The embedded URL also points to an HTML page, further supporting the idea of redirection or content hosting.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://memoryicons.net/uploads/1/3/0/5/130590355/130590355.html#how+to+put+two+pictures+side+by+side+html
    • http://cobberdoglabradoodle.com/uploads/1/3/0/3/130379422/57f78917a57.pdf
    • http://jilleunschmitt.com/uploads/1/3/1/3/131383386/tebatefikozeb.pdf
    • http://thewilkinsonswordshop.com/uploads/1/3/0/4/130483949/tefevelonemefitojopi.pdf
    • http://designingwomenofaz.com/uploads/1/3/0/7/130739723/tokumamizib.pdf
    • http://krishnaandnatansh.com/uploads/1/3/0/9/130970004/4a49a52552b.pdf
    • http://aydenpugh.org/uploads/1/3/0/7/130739128/rupamif_xatipiwila_gasejage_kogepakedavaxi.pdf
    • http://klutch.life/uploads/1/3/0/6/130604531/4300716.pdf
    • http://saritaipale.com/uploads/1/3/0/6/130604639/5dcb4726c.pdf
    • http://basicboekhouding.nl/uploads/1/3/0/8/130874102/givekoxide.pdf
    • http://rcrlogistics.net/uploads/1/3/0/6/130639629/7946727.pdf
    • http://arborealwine.com/uploads/1/3/0/9/130969714/vekelavi-zojapase-bugexulune-melakiduxeme.pdf
    • http://kanskitchen.com/uploads/1/3/1/0/131070167/7527026.pdf
    • http://orlandoclearinspections.com/uploads/1/3/0/6/130604306/wudokas-mixobonapozikar-zilugam.pdf
    • http://foundationrepairinhoustontexas.com/uploads/1/3/0/4/130476237/4166046.pdf
    • http://fairtradersproject.org/uploads/1/3/0/7/130776804/1242019.pdf
    • http://tigergirldesigns.com/uploads/1/3/0/6/130640052/madut.pdf
    • http://sarahlaurencollins.com/uploads/1/3/0/3/130379424/63d3bcd7.pdf
    • http://varandaderetalhos.com/uploads/1/3/0/2/130272242/xokiduj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007fef.bin
928662cfa0c4f9355a1b870bf1e9b196614332b12655c6f3b30b4cad5ab3f024
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FEF 9280 bytes