Malicious PDF — malware analysis report

Static analysis result for SHA-256 c881d6ecd3b35d19…

MALICIOUS

PDF

44.9 KB Created: 2020-03-30 12:00:08 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5b714effb89ad29ac8d934d638b51d21 SHA-1: ac4523cbb97ea86d73597d52d3c85c3083a53f72 SHA-256: c881d6ecd3b35d19d95c00c768af34d7da97cf00cd526e93972d72055db6c624
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, includes a URL related to nursing care in neonates, suggesting a lure. The primary attack pattern involves directing users to a network of linked domains, likely for SEO spam or to host further malicious content. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://advance-it.net/uploads/1/3/0/5/130546076/130546076.html#cuidados+de+enfermeria+en+oxigenoterapia+en+neonatos+pdf
    • http://foreigncanada.com/uploads/1/3/0/6/130639028/nidipek_zasax.pdf
    • http://blisspractice.org/uploads/1/3/0/7/130776769/6346013.pdf
    • http://westernenergy-rd.com/uploads/1/3/0/2/130271190/renaforulatovi.pdf
    • http://littypartyinabox.com/uploads/1/3/0/6/130621576/bedakoka.pdf
    • http://layoverinparistours.com/uploads/1/3/0/5/130550888/fokikajazatewe.pdf
    • http://nightbluesystems.net/uploads/1/3/0/7/130739315/e75bf3.pdf
    • http://tyrajewelrygifts.com/uploads/1/3/0/8/130813055/mulit-rilipives.pdf
    • http://healthandwellnessforum.org/uploads/1/3/0/6/130620909/befovogunonu.pdf
    • http://grizzlyrentalsonline.com/uploads/1/3/0/6/130604177/6153329.pdf
    • http://centrekaizen.net/uploads/1/3/0/5/130550879/bidopabaf-tusurodareri-redogeg-fukotedaj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d27.bin
1583b9d2b11f6ffcc7f3f9de1fec2a653a0eb60b76a31d24f40f5c116e734eb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D27 9344 bytes
font_01_sfnt_off00008f10.bin
2d673730e7616dbc5ddae4cbc9d6720dc9d07d8c4eab51d54849ec9f8b9e166c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F10 16128 bytes