Malicious PDF — malware analysis report

Static analysis result for SHA-256 abbdc8dad3b064eb…

MALICIOUS

PDF

51.2 KB Created: 2020-04-12 16:58:58 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 4b7d27ccc68b15fb49756d0c93faa826 SHA-1: 9fb9c9c29f2b02a5e6ce9dc9593c9435a62df323 SHA-256: abbdc8dad3b064eb36b142ccb7f051723be688254aa197dca0c35c1d9a0cf37f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded links to external websites, masquerading as educational content ('holt geometry lesson 1-5 answers'). The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of these links, suggesting a coordinated effort to direct users to potentially malicious sites. No scripts were extracted from this sample, limiting further analysis of its direct execution behavior.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://yalaarts.com/uploads/1/3/0/3/130313228/130313228.html#holt+geometry+lesson+1-5+answers
    • http://brushhill-rvstorage.com/uploads/1/3/0/4/130494289/tofife_puzege_buvujo_porasemewoxega.pdf
    • http://divadivinecosmetics.com/uploads/1/3/1/4/131483383/silusinizoz-taxipekeloje-lopiv.pdf
    • http://dealingwithstuff.com/uploads/1/3/0/6/130620858/gukunelipamexe.pdf
    • http://bellestarrboutiqueok.com/uploads/1/3/0/4/130483875/pasuv-nozogewirinudu-pepusaxejudofi-judukopuki.pdf
    • http://deepfriednametags.com/uploads/1/3/1/3/131381241/110420.pdf
    • http://agroliber.net/uploads/1/3/0/2/130288551/9001900.pdf
    • http://kidssafeholiday.com/uploads/1/3/0/5/130544379/9870d3babc333f6.pdf
    • http://pl-eshop.me/uploads/1/3/0/6/130605048/3425481.pdf
    • http://moustikair.com/uploads/1/3/0/6/130621867/4163180.pdf
    • http://samihokkanen.com/uploads/1/3/0/7/130775870/453709965.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008586.bin
a9fc260300058cd5a9e7214d77ca6403a7343af058939cf3f6a341c65e52b04f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8586 9560 bytes
font_01_sfnt_off0000a954.bin
b7678d2771a385a873beb44e48e0b809ca1a4ef7fe4b29cdc065bc7f15d31c7c
pdf-font-stream PDF embedded font (sfnt) at offset 0xA954 16568 bytes