Malicious PDF — malware analysis report

Static analysis result for SHA-256 c086653cc8ea88f2…

MALICIOUS

PDF

39.0 KB Created: 2020-05-23 09:47:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6dcb5ffcebd460a955e2b925048a1a6c SHA-1: 88f0d37c09cb6a8e182d412055c802d035b1b013 SHA-256: c086653cc8ea88f27ba23af97b6d3e446f10e9802b1483bc61c75c1a47828746
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of external links to other PDF documents hosted on various domains. This pattern is indicative of a link farm or SEO poisoning technique, designed to drive traffic to these external sites. The document body contains garbled text and the authoring application is wkhtmltopdf, suggesting it was programmatically generated. The primary attack pattern involves redirecting users through this network of links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wellfitforlife.com/uploads/1/3/0/9/130969809/130969809.html#trbuh+bolan+na+dodir+ili+tvrd
    • http://artlynchcoaching.org/uploads/1/3/0/6/130620441/eb5d5db813f2e.pdf
    • http://nomvee.be/uploads/1/3/0/3/130379342/4446416.pdf
    • http://stephaniesolutions.net/uploads/1/3/1/6/131606353/majapujawomaxuv.pdf
    • http://intelligentconstruction.miami/uploads/1/3/1/4/131454482/06df20629d0e898.pdf
    • http://lisasfurbabiespetsitting.com/uploads/1/3/0/6/130621715/ce35bd87.pdf
    • http://zeladvisorygroup.org/uploads/1/3/0/2/130287984/bedirinolazesutedoxu.pdf
    • http://intheworldministries.org/uploads/1/3/0/3/130323600/xonemaz.pdf
    • http://toledosworst.com/uploads/1/3/0/6/130604581/pinelobuzupu.pdf
    • http://dragcrawl.com/uploads/1/3/0/6/130621238/warofew-dilejimisubobu-mizinixinudita.pdf
    • http://speedraw.com/uploads/1/3/0/2/130273584/470cf48d649.pdf
    • http://lgbt2012embassytirana.org/uploads/1/3/0/6/130621695/mavoxofexabuv.pdf
    • http://jennaheinaaho.com/uploads/1/3/1/4/131438604/gimomadaxexe.pdf
    • http://go4launch.net/uploads/1/3/0/2/130289294/korowudukifejejufe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b51.bin
2ac0b6402122b7ae51f79b59e626f6165bdf290ada1e5c5a7f3a955ad6a29aa8
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B51 11212 bytes