Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3b72b5aae26824f…

MALICIOUS

PDF

41.0 KB Created: 2020-06-22 03:42:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9451a594142b897a05e8d3fe19e59cb9 SHA-1: 3309c52d99dcf0ed49ee82ed3574e6770bd5f233 SHA-256: b3b72b5aae26824fc1d2a254e528908ded5ab5fa53c29f85014900c05c1497c3
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or redirection scheme. The document body, though heavily obfuscated, contains URLs that are consistent with the heuristic findings. The primary attack pattern appears to be SEO manipulation or directing users to potentially malicious content hosted on these external sites.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ltdcarib.com/uploads/1/3/1/6/131637125/131637125.html#der+mit+dem+scheich+tanzt+pdf
    • http://cpanel.wafbc.com.au/uploads/1/3/0/2/130291555/6888996.pdf
    • http://mail.ondemandinstruction.com/uploads/1/3/0/2/130287871/8739105.pdf
    • http://agencepro-pose.com/uploads/1/3/1/8/131857818/wugivufomusan.pdf
    • http://mercyhealthfreeclinic.com/uploads/1/3/1/1/131164317/67bda.pdf
    • http://iamfleeklord.com/uploads/1/3/0/8/130873875/6bb5794.pdf
    • http://74-123-73-221.mgwnet.com/uploads/1/3/1/6/131636833/vuromifob_nigajomoxune_gifubasufu_xuwenufulorekil.pdf
    • http://exchange19.ccfiji.com/uploads/1/3/0/7/130774964/7610354.pdf
    • http://ewwcrust.com/uploads/1/3/0/8/130813740/wijekowofetigigamab.pdf
    • http://libbysdance.com/uploads/1/3/0/4/130483872/ludipisawuji-viteral-zabifafanenuv-fujagemikimi.pdf
    • http://admin.moulinbertrand.com/uploads/1/3/0/9/130969012/mafera-rodatuj-majibewaziz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005d26.bin
c7295c2388a59ceb570c134d3050c26c16bfa6828ae0e4740120d7798bca2701
pdf-font-stream PDF embedded font (sfnt) at offset 0x5D26 5088 bytes
font_01_sfnt_off00006e50.bin
05f80f64c8a9b075c6fb5e0ad07dcd942b0f53d2e534304259702e22d8d2517c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E50 12024 bytes