Malicious PDF — malware analysis report

Static analysis result for SHA-256 b637c75ab59d0ea6…

MALICIOUS

PDF

54.3 KB Created: 2020-03-30 07:11:22 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 50434694af197aa9285529643001679f SHA-1: 99d7cc55a3ebcb5ce7d78994e63236964d742309 SHA-256: b637c75ab59d0ea6a6f25efb0308e62ed6cddeb771f62e418f9bf8f1b97fb1df
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, disguised as a web design tutorial. The heuristic PDF_SEO_LINK_FARM indicates a link farm, suggesting the document's primary purpose is to redirect users to potentially malicious websites. The PDF_ACTION_PARSER_EVASION heuristic further suggests an attempt to evade detection. The embedded URLs are likely used for phishing or distributing further malware.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://74-123-72-13.mgwnet.com/uploads/1/3/1/3/131383515/131383515.html#web+design+tutorial+pdf
    • http://priorityshipping.us/uploads/1/3/0/6/130604233/ecbf5.pdf
    • http://merryleetraum.net/uploads/1/3/0/8/130874204/vizopupeviv-xobinivor-lifipogisowu.pdf
    • http://ashley-champagne.com/uploads/1/3/0/6/130605097/poravejodas-lanirarejujotu-suxipuwogesuw.pdf
    • http://fragcreation.com/uploads/1/3/0/5/130539679/2407934.pdf
    • http://mp-cnc-design.com/uploads/1/3/0/3/130379239/xeravozekepeze-zuvulalu.pdf
    • http://tuliptreatments.com/uploads/1/3/0/6/130639947/5236626.pdf
    • http://ajshomebakedmore.com/uploads/1/3/0/5/130545260/refejosufosori.pdf
    • http://globalcoach.online/uploads/1/3/0/6/130621589/xaxak.pdf
    • http://bakersfieldtrees.com/uploads/1/3/0/4/130483132/sadez.pdf
    • http://giftsofgrace.com/uploads/1/3/0/6/130620633/4620612.pdf
    • http://motionsole.com/uploads/1/3/0/6/130620841/jagilovunor.pdf
    • http://celesteenriquez.com/uploads/1/3/0/2/130289262/xibufofidaziw-baxad-tasijejexon-namiwovalefo.pdf
    • http://noradragoon.com/uploads/1/3/0/3/130379354/juzimed_kelovemosenu_koxafamule.pdf
    • http://www.lucyserrands.com/uploads/1/3/0/3/130313057/zanika-vewozatod-tilexejoz.pdf
    • http://ashasanctuary.org/uploads/1/3/0/7/130775108/5460977.pdf
    • http://rosebeltradesolutions.com/uploads/1/3/0/8/130814070/kajulibu.pdf
    • http://voyagerclassicalacademy.com/uploads/1/3/0/6/130604812/gudipuni-tiwejogidu-kofaruvivewovo.pdf
    • http://lateralliving.net/uploads/1/3/0/5/130545096/vuguxizij.pdf
    • http://deepcreekph.com/uploads/1/3/0/4/130477702/16c7298da6b.pdf
    • http://samanthajoyphotography.com/uploads/1/3/0/4/130476740/7862437.pdf
    • http://comstar-global.com/uploads/1/3/0/2/130289455/63f63.pdf
    • http://sagecrystaltraining.com/uploads/1/3/0/5/130545493/moxolijigon-vujixaruz-roritovuva.pdf
    • http://mosaicskinandbody.com/uploads/1/3/0/6/130605344/lusowasogepo-togiboteva-jipusa-firozajozin.pdf
    • http://mosaicskinandbody.com/uploads/1/3/0/6/130605344/lusowasogepo-to
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000095bb.bin
434af6bcbe1851846bad580299e45eb24ab332bf164612b0314692e31c596e32
pdf-font-stream PDF embedded font (sfnt) at offset 0x95BB 8088 bytes
font_01_sfnt_off0000b4e8.bin
c6c28444bcd94379862b6cc7f8cfcdbcdaeb026857ccdb099d87626a561054a6
pdf-font-stream PDF embedded font (sfnt) at offset 0xB4E8 16092 bytes