Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5ab0aa373340f48…

MALICIOUS

PDF

130.6 KB Created: 2020-05-18 08:28:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 66af09603f8f0bda4de65701e883c333 SHA-1: c71af0de83a6ce6c4eac1c14e0895bbda5407dfd SHA-256: b5ab0aa373340f481f814b0146da443a2b200043f91ead37dcd85faed10de711
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or redirection strategy. The embedded URL 'http://becdaxis.com/uploads/1/3/0/5/130551567/130551567.html#the+iroquois+constitution+pdf+answers' is particularly notable. The document body is heavily obfuscated, but the presence of these links strongly indicates a malicious intent to drive traffic or distribute further payloads.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://becdaxis.com/uploads/1/3/0/5/130551567/130551567.html#the+iroquois+constitution+pdf+answers
    • http://guarantorfinder.com/uploads/1/3/1/4/131483020/fuvixegur.pdf
    • http://crowdance.com/uploads/1/3/1/3/131380916/3315810.pdf
    • http://mcl1009.org/uploads/1/3/1/3/131379277/0bf71d.pdf
    • http://golfviewvillaflorida.com/uploads/1/3/1/0/131071288/649263.pdf
    • http://lmhrealtyservices.net/uploads/1/3/0/6/130640182/2737055.pdf
    • http://alittlewanderess.com/uploads/1/3/1/4/131453530/dizuzapu.pdf
    • http://bimaservices.net/uploads/1/3/0/8/130813478/diwekerowi-pakikefuxamijo-xosanosux.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001d7b0.bin
b553933f368d1464165bbbfc0c736864134ba61a9ef019c1edd8575047d3bee7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D7B0 11732 bytes