Malicious PDF — malware analysis report

Static analysis result for SHA-256 c605186cb610dc08…

MALICIOUS

PDF

44.3 KB Created: 2020-06-25 08:45:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5ed236977a2ca2958a2c5e277426fd73 SHA-1: 137a226dcb36893df5145cdad1ae0c8f4c6271ec SHA-256: c605186cb610dc080642c551ecac6fa4cc0bb27387f1613181b271267487cc98
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, a technique often used for SEO spam or to redirect users to malicious sites. The document body, though partially corrupted, contains references to 'Openoffice org base guide' and URLs that appear to be part of a link farm. No scripts were extracted from this sample, limiting the analysis of direct malicious actions.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://takeflightsweettreats.net/uploads/1/3/1/3/131383751/131383751.html#openoffice+org+base+guide
    • http://mase.ph/uploads/1/3/0/5/130588640/5976a4c830663ac.pdf
    • http://osteopathie-ullmann.de/uploads/1/3/0/5/130541950/9660262.pdf
    • http://goodsamrehabilitation.org/uploads/1/3/1/0/131070305/6305692.pdf
    • http://lynnphysical.com/uploads/1/3/0/9/130969116/segob.pdf
    • http://chiboutique.net/uploads/1/3/0/7/130776307/5738294e.pdf
    • http://missionmobilizationjonasmuyima.org/uploads/1/3/1/4/131407135/nebinij.pdf
    • http://mail.fatherjim.com/uploads/1/3/0/8/130874629/50f821448a331c.pdf
    • http://dialtransportllc.com/uploads/1/3/0/2/130289453/376c90c9b3c049.pdf
    • http://blisspropertydesign.com/uploads/1/3/0/7/130739974/medepixub.pdf
    • http://ohio-dogbite.com/uploads/1/3/1/4/131455734/virexad-fusexo-ximusinu-kilodujur.pdf
    • http://dependsontheday.co.uk/uploads/1/3/0/4/130477864/xivazademabo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a2e.bin
e2489710e440eaf92663e8eb5d1599e0b112fd29d733d42bdb3869a2500ee45f
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A2E 5260 bytes
font_01_sfnt_off00006c04.bin
ace0a0f338241cb9b27ee4cc93a4489103a59f1b76f6c08a350eded59fa0f54e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C04 18640 bytes