Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2001d1880506241…

MALICIOUS

PDF

51.1 KB Created: 2020-04-02 04:54:46 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: feb20a112093ad8cfe1f1c8ebb9ab0e9 SHA-1: 9c64367ccfdf6f253cfdba5b7282f728fe14838f SHA-256: c2001d188050624173307583a3b4ccda888387a97340d90969973eb3e2da390b
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains a large number of external links, forming a link farm. The primary heuristic indicates a "PDF_SEO_LINK_FARM" which suggests the document is designed to drive traffic to numerous other PDF files hosted across various domains. The embedded URLs and the document body text, though partially corrupted, contain references to these external links, reinforcing the link farm attack pattern. No scripts were extracted, limiting further analysis of payload delivery.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://whitemanwaking.com/uploads/1/3/0/4/130476468/130476468.html#entrevista+encuesta+cuestionario+observacion
    • http://edwardfunkhouserofficial.com/uploads/1/3/0/6/130621610/7f078101.pdf
    • http://arfpetfoods.ca/uploads/1/3/0/3/130324072/4b3b28bca10bda6.pdf
    • http://theworldunplugged.org/uploads/1/3/0/8/130874347/boroxaxawab.pdf
    • http://bessiebluedesigns.com/uploads/1/3/0/3/130313082/guverebokapelam.pdf
    • http://chaplainkelly.com/uploads/1/3/0/5/130589187/tufituxon-xifexejifulejad-dikosali.pdf
    • http://nassaufencing.com/uploads/1/3/0/2/130289239/pebiwaridit.pdf
    • http://getquicklabs.com/uploads/1/3/0/9/130969446/9733454.pdf
    • http://gemehi.com/uploads/1/3/0/6/130621698/6ebc5c5216d.pdf
    • http://fatwoodexpress.com/uploads/1/3/0/7/130740124/8025746.pdf
    • http://evangelizeme.com/uploads/1/3/1/3/131383726/270112a.pdf
    • http://thelagoonsedge.com/uploads/1/3/0/7/130775841/7648143.pdf
    • http://toogiephotography.com/uploads/1/3/1/0/131070733/5a598e.pdf
    • http://rodgersandcoonline.com/uploads/1/3/0/8/130814295/7549747.pdf
    • http://3epourtous.org/uploads/1/3/0/4/130476921/846e1a37d22c.pdf
    • http://msjsport.net/uploads/1/3/0/6/130604881/4520437.pdf
    • http://possibilideas.net/uploads/1/3/0/6/130605019/235e7388cba01.pdf
    • http://northwestpolebuildings.com/uploads/1/3/0/3/130313803/5383842.pdf
    • http://lawyersmanila.com/uploads/1/3/0/6/130604420/tetejut_domuwozu_zewile_fojunurajirotag.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000091df.bin
b30715a2483b3804b8a6293a385d523873994bfd98e6f6b0c06b05d6653916ef
pdf-font-stream PDF embedded font (sfnt) at offset 0x91DF 1660 bytes
font_01_sfnt_off000099d5.bin
c6284501b5795633499777f38ca361f4c9c77f16d0bb11459065cdc1f62879c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x99D5 9780 bytes