Malicious PDF — malware analysis report

Static analysis result for SHA-256 cafbc50c52fe6d9e…

MALICIOUS

PDF

46.0 KB Created: 2020-05-14 09:59:43 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 547842ff42a39a908c6ce9f21a0edf0a SHA-1: 4c4a8e797e8f5f0b9d22a6f8d11888eb0e2ebf30 SHA-256: cafbc50c52fe6d9e610cfb2fc9ef49114cd7d6d7935b77c0ad2586b199c1457a
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, many of which point to other PDF files on different domains. This is indicative of a link farm or SEO spam tactic. The document body, though heavily obfuscated, contains references to 'Hypercalcemia nice guidelines' and the wkhtmltopdf application, suggesting a lure to potentially malicious content hosted on the linked domains. The primary intent appears to be driving traffic to these external sites, possibly for further exploitation or malicious content delivery.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://swcounselingexam.com/uploads/1/3/1/1/131164066/131164066.html#hypercalcemia+nice+guidelines
    • http://foster-found.com/uploads/1/3/0/8/130814682/5476180.pdf
    • http://fydoonline.com/uploads/1/3/0/6/130604771/1745217.pdf
    • http://sqonecondos.com/uploads/1/3/0/7/130738885/vafosodekagixuw.pdf
    • http://neilwperssoncpa.net/uploads/1/3/1/4/131437655/8976630.pdf
    • http://exolus.com/uploads/1/3/0/7/130775308/nifixanoxosewenupu.pdf
    • http://nurasmimarlik.com/uploads/1/3/0/7/130738603/1595328.pdf
    • http://whitneyelliott.com/uploads/1/3/0/7/130775551/6410286.pdf
    • http://luiscunha.net/uploads/1/3/0/7/130740434/a4025c0bb.pdf
    • http://astromarket.space/uploads/1/3/0/9/130969938/gegar.pdf
    • http://pitch-plan.com/uploads/1/3/1/3/131398359/5195899.pdf
    • http://rachelsiemens.com/uploads/1/3/0/4/130493968/8326193.pdf
    • http://archerypartyhouston.com/uploads/1/3/1/4/131453016/f17ff74.pdf
    • http://sslawncare.net/uploads/1/3/0/5/130588269/8226263.pdf
    • http://nationalcrossday.com/uploads/1/3/0/4/130483134/lebubelewares.pdf
    • http://wherethesidewalkendsphoto.com/uploads/1/3/0/3/130313459/34543d1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000885a.bin
31722e0f3bebc2273d9dceab5f97290d43188882af1c006361a80fbea99ab105
pdf-font-stream PDF embedded font (sfnt) at offset 0x885A 10588 bytes