Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7e677b7f33867c2…

MALICIOUS

PDF

29.9 KB Created: 2020-04-08 13:03:12 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 567a46118a58cd6cd1d17951c843644c SHA-1: e9c0f6358e0c5ba1b1718e787f6258836d0a0f84 SHA-256: b7e677b7f33867c25798531466d44d3ebd6f87f0a681b5518ce98a9d7a94c244
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or redirection scheme. The embedded URLs are likely used to lure users into downloading or accessing further malicious content. No scripts were extracted from this sample, limiting the analysis of direct execution capabilities.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jr-group.org/uploads/1/3/0/7/130740189/130740189.html#do+while+loop+continue+java
    • http://ster-o-wave.com/uploads/1/3/0/2/130288571/56c8dd9.pdf
    • http://nychooloflaughteryoga.com/uploads/1/3/0/2/130271002/7686810.pdf
    • http://birdholidays.eu/uploads/1/3/0/4/130477979/lirid-batetakajinemuv-zepun.pdf
    • http://bluecrossflooring.com/uploads/1/3/0/4/130483426/medojinimubax.pdf
    • http://ns2.brittpropack.com/uploads/1/3/0/9/130969034/sekugobetelabob.pdf
    • http://metalockinternational.net/uploads/1/3/0/7/130739476/nigolazilusidijuga.pdf
    • http://exactowash.com/uploads/1/3/0/6/130639743/5298824.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004e99.bin
bf50f915eefc723be2caecbe76514c7daf098ee675a07636025a51695248c8fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x4E99 7324 bytes