Malicious PDF — malware analysis report

Static analysis result for SHA-256 bcb43dac8eada5a8…

MALICIOUS

PDF

42.2 KB Created: 2020-03-29 06:45:58 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 7b2cf6c1b4e819f0e0ffb98c33819d8b SHA-1: 325a848555b2a8086024bdac903e5819e5658d5f SHA-256: bcb43dac8eada5a83e26feeb7c7a6e9feeb71c4b5f59b324bf5f555993a1a8d3
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a lure promising free software product keys, directing users to external URLs. The PDF_SEO_LINK_FARM heuristic indicates a large number of embedded links, likely for SEO manipulation or to distribute malicious content. The primary URL identified is http://www.ebzgrp.com/uploads/1/3/0/5/130590403/130590403.html#free+working+product+key+for+microsoft+office+2010+professional+plus, which is part of a link farm hosted on httpsecurityscan.com.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ebzgrp.com/uploads/1/3/0/5/130590403/130590403.html#free+working+product+key+for+microsoft+office+2010+professional+plus
    • http://httpsecurityscan.com/uploads/1/3/0/6/130639859/9293432.pdf
    • http://classicalgems.net/uploads/1/3/0/2/130289800/02f38.pdf
    • http://stage.hempnu.com/uploads/1/3/0/2/130270812/dewidanek.pdf
    • http://blingbombringbombs.com/uploads/1/3/0/5/130543870/9679023.pdf
    • http://thecompassionateasskicker.net/uploads/1/3/0/7/130739509/8402338.pdf
    • http://lussomakeup.com.au/uploads/1/3/0/2/130270911/5945471.pdf
    • http://hostmaster.charitytrainingservices.com/uploads/1/3/0/2/130289748/nafawobipave.pdf
    • http://das-llc.com/uploads/1/3/0/7/130775584/4942433.pdf
    • http://setfreeindeed.com/uploads/1/3/0/7/130739061/3979845.pdf
    • http://customhomeimprovements.org/uploads/1/3/0/5/130589397/tadowadomufa_puzakini.pdf
    • http://www.thebrewshopsavannah.com/uploads/1/3/0/8/130874119/rovilodasog.pdf
    • http://prairieporch.shop/uploads/1/3/0/7/130776602/sigaliko.pdf
    • http://treeservicehialeah.com/uploads/1/3/0/6/130621142/nezemu.pdf
    • http://a2ndlook.shop/uploads/1/3/0/5/130588173/5736681.pdf
    • http://www.ilspiritofficials.com/uploads/1/3/0/4/130435589/9308525.pdf
    • http://www.newbeginningschristiancounselingllc.com/uploads/1/3/0/6/130640162/ff009.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007c66.bin
d022f75bee9dbc89121a304d4a145e2052dcb04a87b719af54194dedc83b661e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C66 7844 bytes