Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8cd43506716514e…

MALICIOUS

PDF

83.5 KB Created: 2020-03-25 08:24:57 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 40c2dd6479747f0f9095a88c3dba9a50 SHA-1: 97eed56dcea1a6662727dc81871a6b527400ba2d SHA-256: a8cd43506716514e6565e9d11ca218af57baa269f9de2bd7f93500cdf19189f5
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, indicating a link farm strategy. The primary heuristic identified a mass external PDF link farm hosted on 'aeiconicday.com'. The embedded URLs point to various domains, suggesting an attempt to distribute traffic or host content across multiple sites. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thebeautycave.net/uploads/1/3/0/4/130436137/130436137.html#%D9%88%D8%A7%D8%AA%D8%B3+%D8%A7%D8%A8+%D9%84%D9%84%D9%83%D9%85%D8%A8%D9%8A%D9%88%D8%AA%D8%B1+%D9%88%D9%8A%D9%86%D8%AF%D9%88%D8%B2+7+%D8%A8%D8%AF%D9%88%D9%86+%D9%87%D8%A7%D8%AA%D9%81
    • http://aeiconicday.com/uploads/1/3/0/6/130604938/314307.pdf
    • http://craigsthornton.com/uploads/1/3/0/5/130550971/roxowe.pdf
    • http://thvpnt.com/uploads/1/3/0/7/130739116/gekofax.pdf
    • http://mta-sts.mx.drmandiegillette.com/uploads/1/3/0/3/130313495/duxaganotonapow.pdf
    • http://www.soaringheartsent.com/uploads/1/3/0/5/130541004/zofijexur.pdf
    • http://danofordings.com/uploads/1/3/0/6/130639268/felaw-pabilasutiza-latagofupad.pdf
    • http://parisglam.com/uploads/1/3/0/9/130969130/7680475.pdf
    • http://corretorjclaudioimoveis.com/uploads/1/3/1/0/131069777/tifilak_widepobawave_dozositunam_kaxaz.pdf
    • http://caketotherescue.net/uploads/1/3/0/2/130289247/piponogalejepin-nakilatip.pdf
    • http://mail.davisbands.org/uploads/1/3/0/5/130589097/xivufavavejifa.pdf
    • http://hdtechtalk.com/uploads/1/3/0/6/130639565/3089698.pdf
    • http://www.hhmedtransport.com/uploads/1/3/0/7/130775404/pofedodaw_ninetuve_pidupedar_jumob.pdf
    • http://northelkinchurch.org/uploads/1/3/0/7/130739398/2f0f2e594.pdf
    • http://thebarefootgal.com/uploads/1/3/1/1/131164250/a6120f.pdf
    • http://stricklandskennels.net/uploads/1/3/0/6/130620839/9545274.pdf
    • http://broyagebeauregard.com/uploads/1/3/0/6/130621000/xonumupogok.pdf
    • http://www.teitsson.com/uploads/1/3/0/6/130640025/8996312.pdf
    • http://iowabirthactivists.org/uploads/1/3/0/3/130379158/tifilo_buvinug_luponaxabuni_sogilud.pdf
    • http://comonativo.com/uploads/1/3/0/7/130738569/2b7fcc683.pdf
    • http://nathanraywilkerson.com/uploads/1/3/0/2/130289304/navaf.pdf
    • http://whiteisleproperties.com/uploads/1/3/0/6/130621116/4620202.pdf
    • http://www.thelashwear.com/uploads/1/3/0/8/130874326/xanir.pdf
    • http://www.splendorosa.com/uploads/1/3/0/2/130289540/muxejigera.pdf
    • http://mail.lcoproductions.net/uploads/1/3/0/4/130489803/sutigasizudexom_jedolumelax_visezefezu_pizikaz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off000104f6.bin
5f5d34ec37313eb11d5b5d9ff6ba88087973c8dc7bbe41d6a5b65889c54744d5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x104F6 31564 bytes
font_00_sfnt_off0000e89b.bin
5f8ea048543c511e0b4ccc23f9549e64b2006a8f22d9c253d74c592c9939aa76
pdf-font-stream PDF embedded font (sfnt) at offset 0xE89B 7196 bytes