Malicious PDF — malware analysis report

Static analysis result for SHA-256 bfd09cd439e1b14d…

MALICIOUS

PDF

49.7 KB Created: 2020-04-01 17:17:07 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 4b2d16266ea0860994a1f6718583fd49 SHA-1: 01e88d16e7e861098b0f3ddbe45e584573af7802 SHA-256: bfd09cd439e1b14da94c87ddc90386c2c9266aea96645490890947e9672e8d52
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The document body itself contains text related to computer output devices and authoring application details, but the primary malicious activity appears to be the distribution of numerous links. The heuristic indicates a link farm, suggesting the purpose is to drive traffic or host potentially malicious content on these external sites.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://slbconsultingservices.com/uploads/1/3/1/1/131164278/131164278.html#10+dispositivos+de+salida+del+computador
    • http://ritabaumann.net/uploads/1/3/0/3/130313314/zesuzopi-sabiretumo-denanakone.pdf
    • http://tabithafoundation.net/uploads/1/3/0/4/130476821/tizesugofikiwob_gufawuluniki_juxod.pdf
    • http://royalbeautyxchange.com/uploads/1/3/0/6/130639468/mikedeguguwobo-pujimitekujane-kelupo.pdf
    • http://dreamyclean.net/uploads/1/3/0/6/130604314/zuralaxomawi.pdf
    • http://bretthalbleib.com/uploads/1/3/0/6/130603891/juvet-modeniwef-bidakifomidi-jazigo.pdf
    • http://terrifictripshome.com/uploads/1/3/0/5/130546000/2283744.pdf
    • http://lavc24-7.com/uploads/1/3/0/3/130323253/terejebuja_zawirenufijegig_wewifodevemom_xijaxanakuweser.pdf
    • http://bemotrip.com/uploads/1/3/0/6/130639147/d3da383dc377.pdf
    • http://smartpt.org/uploads/1/3/0/7/130775634/depaxaxener-pureduribaw.pdf
    • http://80e20.ch/uploads/1/3/0/7/130738576/puwarevufi.pdf
    • http://gas-p.com/uploads/1/3/0/7/130738503/moginutowirew.pdf
    • http://acmechanical.org/uploads/1/3/0/2/130289232/wuremolulugi.pdf
    • http://kongsvape.com/uploads/1/3/0/9/130969027/2663337.pdf
    • http://stardate0001.us/uploads/1/3/0/3/130313728/2d3fe8dd6a6ca93.pdf
    • http://finesseconsultingengineers.com/uploads/1/3/0/6/130605314/9663090.pdf
    • http://openspacesorganizing.com/uploads/1/3/0/8/130874153/dizejatedatago-mosijenuzopakev.pdf
    • http://570dj.com/uploads/1/3/0/6/130621606/bavowegevudef-jakenifupixovo-sagatewadeboge.pdf
    • http://businessbydegree.org/uploads/1/3/0/6/130604871/7778452.pdf
    • http://hardwoodflooringsouthfield.com/uploads/1/3/0/2/130289353/09b4934e6.pdf
    • http://temploobaife.com/uploads/1/3/0/3/130379353/4459548.pdf
    • http://impresstosell.com/uploads/1/3/1/0/131070926/gobazesafasow_nasop_wunekufabef_nezefon.pdf
    • http://globalafricancreates.com/uploads/1/3/0/9/130970016/a5f22d7e117495.pdf
    • http://amytharrington.com/uploads/1/3/0/7/130740022/zijarubuf.pdf
    • http://handmadebysoosh.com/uploads/1/3/0/5/130589160/7164235.pdf
    • http://globalafricancreates.com/uploads/1/3/0/9/130970016/a5f22d7e
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008240.bin
58a4d73a6b43aff68d19cfdafe688b287a4a1f44fd43ea754925128b247caa4c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8240 9068 bytes
font_01_sfnt_off0000a33a.bin
f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
pdf-font-stream PDF embedded font (sfnt) at offset 0xA33A 16204 bytes