Malicious PDF — malware analysis report

Static analysis result for SHA-256 c19fdf4be74718f8…

MALICIOUS

PDF

47.9 KB Created: 2020-03-15 13:46:11 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 942e8a0a794fa9cf89d2711e398271b9 SHA-1: 9381526ca99dde681baf71ea35e6e96580801eee SHA-256: c19fdf4be74718f8c09c4d64112aa297767f510433034053ce8b3ce213dea986
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains a mass of external links, a common technique for SEO poisoning or redirecting users to malicious sites. The document body mentions 'Parquet file format pros and cons', likely a lure to encourage clicks on the numerous embedded URLs. No scripts were extracted, and the primary malicious activity appears to be the distribution of links to potentially harmful content hosted on various domains.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://inwardvision.com/uploads/1/3/0/4/130483368/130483368.html#parquet+file+format+pros+and+cons
    • http://mclennanfarms.com/uploads/1/3/0/3/130379503/gosumisujepis-vopez.pdf
    • http://free-fax-service.anyball.info/uploads/1/3/0/5/130544751/lanipedolodevumofo.pdf
    • http://wickedporch.com/uploads/1/3/1/0/131070027/2e6fa85eef123.pdf
    • http://gratefulvet.com/uploads/1/3/0/7/130776645/tofuximumef_jumemireki_xuvosunixeki_venidebozo.pdf
    • http://myempoweringyouth.com/uploads/1/3/0/6/130621303/palubinaz.pdf
    • http://aliveyouthmebc.com/uploads/1/3/0/3/130379138/nosasodagibuguzoba.pdf
    • http://www.ipsma.info/uploads/1/3/0/4/130489536/e94ce340d.pdf
    • http://vivaescapes.com/uploads/1/3/0/8/130874318/xunugofaw.pdf
    • http://eastcorkpayroll.ie/uploads/1/3/0/5/130546971/sanuwiziweguwu-daditudaj-manasenomiz.pdf
    • http://hasbropowerrangers.com/uploads/1/3/0/4/130483329/gosumin.pdf
    • http://jenreidphotoart.com/uploads/1/3/0/7/130740158/kemaminopove_xuwebisal_binoxevewiz_gafak.pdf
    • http://styleforlower.com/uploads/1/3/0/4/130435757/2063858.pdf
    • http://gallaghersculpture.com/uploads/1/3/0/4/130490218/ledilewojowujog.pdf
    • http://vnunitedfc.org/uploads/1/3/0/9/130969850/9469173.pdf
    • http://cairnscloudsolutions.com/uploads/1/3/0/6/130604764/sazuw.pdf
    • http://moosetracksmi.com/uploads/1/3/0/6/130639573/fapilomu.pdf
    • http://experiencemeaning.com/uploads/1/3/0/2/130289485/6838331.pdf
    • http://moonlightplanners.com/uploads/1/3/0/6/130620313/wonofasa-loxurilumap.pdf
    • http://manetaspark.net/uploads/1/3/1/0/131070493/c0ead140b5c5136.pdf
    • http://anewhumanity.org/uploads/1/3/0/7/130739333/kuzusoson.pdf
    • http://ns1.xmobilepro.net/uploads/1/3/0/5/130543684/putajibagomara_wedavutat.pdf
    • http://karrinheappey.com/uploads/1/3/0/4/130483417/roziziv.pdf
    • http://myssample.com/uploads/1/3/0/6/130620926/bafupenur.pdf
    • http://iusedtobetechnical.com/uploads/1/3/0/6/130639622/666af32.pdf
    • http://a-custom-esl-tutoring.com/uploads/1/3/0/7/130739917/nedarokoboxibin-zugejituxudeboz-gogutexaveduto.pdf
    • http://iusedtobetechnical.com/upl
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000905b.bin
e21a8d7df1a87a0ae197f045f2a44f3111ed12a2a8f676f0f82b8f24c7311d85
pdf-font-stream PDF embedded font (sfnt) at offset 0x905B 8792 bytes