Malicious PDF — malware analysis report

Static analysis result for SHA-256 adb94f15eec93e71…

MALICIOUS

PDF

37.2 KB Created: 2020-03-22 07:09:26 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5b10ba54265bd30946f0893792a73536 SHA-1: acf2e8885ea50b7d6bcc9d0c89e71bb59170f81f SHA-256: adb94f15eec93e715f36445367299257a51689d3de98948170d61f61a4c32b24
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to PDF files hosted on various domains. The document body contains a reference to 'Lg soundbar nb3530a factory reset', suggesting a lure to trick users into clicking on these links for product support or troubleshooting. The heuristic 'PDF_SEO_LINK_FARM' indicates a deliberate attempt to create a large number of links, likely for SEO manipulation or to distribute malicious content across many domains. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bigdsuperfoods.com/uploads/1/3/0/6/130603917/130603917.html#lg+soundbar+nb3530a+factory+reset
    • http://hostmaster.jetztleben.at/uploads/1/3/0/5/130540049/8043752.pdf
    • http://www.publicatmessag.com/uploads/1/3/0/8/130814085/4968416.pdf
    • http://checkitout.online/uploads/1/3/0/5/130589315/gumuxinalezunozodog.pdf
    • http://www.honey-blossom-boutique.com/uploads/1/3/0/5/130551185/9511569.pdf
    • http://sdatasystems.us/uploads/1/3/0/7/130775808/fevasekinerut_weguf.pdf
    • http://theinformaters.com/uploads/1/3/0/6/130604769/togadujil-bitisagele-zagusekuwefoji.pdf
    • http://guilitherapy.com/uploads/1/3/1/0/131069906/6165524.pdf
    • http://www.cashwithoptions.com/uploads/1/3/0/3/130313106/8d596b4af.pdf
    • http://www.hannapachman.org/uploads/1/3/0/9/130969334/27230c9d7e.pdf
    • http://mta-sts.mx.emmatc.com/uploads/1/3/0/6/130621946/toruwepodazewo.pdf
    • http://genoareview.com/uploads/1/3/0/8/130873914/08e4cc92d3536ef.pdf
    • http://gsiprestige.com/uploads/1/3/0/8/130873868/derim.pdf
    • http://www.annejacobschiropodyandpodiatry.com/uploads/1/3/0/9/130969834/nipanuxuj-punodulodatitis.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000692b.bin
e7c081b9dd517c3db02981e2d425f1b0210f5626a5aa4ea70325e18ae19be7f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x692B 7840 bytes