Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdf63b2d026b399f…

MALICIOUS

PDF

40.9 KB Created: 2020-06-04 05:51:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8b07638f48ea70729d42e114f6404269 SHA-1: d583284eb44540154b889743fd5218c7f42fce5c SHA-256: bdf63b2d026b399f5b013ba0e02f358bb45bca44bd1417996fb59d3de5816951
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links pointing to various domains, indicating a link farm or SEO manipulation tactic. The primary heuristic identified a mass of external PDF links, with 'pmustudio.net' being a dominant host. The document body, though heavily obfuscated, contains references to the URLs, suggesting they are integral to the file's purpose. No scripts were extracted, and the file itself is generated by wkhtmltopdf, suggesting it's a delivery vehicle for these links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://74-123-78-29.mgwnet.com/uploads/1/3/1/8/131871814/131871814.html#night+literature+guide+secondary+solutions+answers
    • http://pmustudio.net/uploads/1/3/0/4/130483634/vimeral.pdf
    • http://cpanel.fujifilmreviews.com/uploads/1/3/0/6/130621941/7396432.pdf
    • http://pointfiftytwo.com/uploads/1/3/0/4/130490488/zenefogojo.pdf
    • http://sigoaprendiendo.com/uploads/1/3/0/7/130775927/5502996.pdf
    • http://sexymorv.com/uploads/1/3/0/5/130542991/d1ddc.pdf
    • http://starbagsptsd.com/uploads/1/3/0/5/130550683/3346493.pdf
    • http://sx.undesirable.us/uploads/1/3/0/2/130289551/9116846.pdf
    • http://hyperdrivehistory.com/uploads/1/3/1/8/131871909/fituligitosoxatid.pdf
    • http://beautifullyradiant.org/uploads/1/3/0/6/130603676/7531217.pdf
    • http://healthybitesnutritionservices.com/uploads/1/3/0/3/130313567/5403010.pdf
    • http://mail.pamaplefestival.com/uploads/1/3/1/6/131608017/7100241.pdf
    • http://74-123-78-29.mgwnet.com/uploads/1/3/1/8/131871814/terms.html
    • http://74-123-78-29.mgwnet.com/uploads/1/3/1/8/131871814/dmca.html
    • http://74-123-78-29.mgwnet.com/uploads/1/3/1/8/131871814/policy.html
    • http://sx.undesirable.us/uploads/1/3/0/2/130289551/9
    • https://poginuwikola.files.wordpress.com/2020/06/50087632796.pdf
    • https://lafukaraziba.files.wordpress.com/2020/06/popotifevumigamemodixit.pdf
    • https://segurako57848594.files.wordpress.com/2020/06/tamakugetidimaxomosol.pdf
    • https://xilejabugagu.files.wordpress.com/2020/06/vowadeta.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000072b4.bin
47b5a0b2f7c96793cfb9ce1a344371a62e6762f7204b4a7110034c7b00248a98
pdf-font-stream PDF embedded font (sfnt) at offset 0x72B4 10708 bytes