Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdf96ea3c041c906…

MALICIOUS

PDF

38.2 KB Created: 2020-06-13 19:05:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6b94eb93fc79564e50b4751d0d1bf63e SHA-1: 1263c01bb6f005e5f6dce6e1b585b08937a43bee SHA-256: cdf96ea3c041c90696e98068d0243be0989f38340402837fbb4abb0aa813061e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO manipulation tactic. The document body itself is largely unreadable, but the presence of numerous URLs strongly implies an attempt to redirect users to potentially malicious or deceptive content. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mail.stoney.art/uploads/1/3/0/8/130874678/130874678.html#frise+chronologique+des+v%25C3%25A9los
    • http://greylockband.com/uploads/1/3/0/6/130604326/7fa921c83d.pdf
    • http://dmkhzge.sites.logojoy.com/uploads/1/3/0/6/130604198/guvejodak_jizudorad_bexirenovaw_zipuz.pdf
    • http://divetechnical.com/uploads/1/3/0/7/130776553/1534891.pdf
    • http://mail.visionsofadventure.com/uploads/1/3/1/0/131071183/tokelupirebedus.pdf
    • http://genesisinstitute.net/uploads/1/3/0/6/130620543/mavojekufolopurine.pdf
    • http://charlestonmanufacturingcenter.com/uploads/1/3/0/8/130873769/9349683.pdf
    • http://mta-sts.mx.motivationgenome.com/uploads/1/3/0/2/130271214/7406783.pdf
    • http://southernfarmandgarden.com/uploads/1/3/0/6/130604220/fa79a0.pdf
    • http://sydney.awrc.org.au/uploads/1/3/0/6/130604355/7b593c1.pdf
    • http://karleymoody.com/uploads/1/3/0/7/130775510/2952c97028bd0e.pdf
    • http://renewablescopywriter.co.uk/uploads/1/3/1/8/131856042/3518794.pdf
    • https://dimepixexam920921294.files.wordpress.com/2020/06/mixokunuguturadodabu.pdf
    • https://legidisupim.files.wordpress.com/2020/06/nepatebitedifumetisuxi.pdf
    • https://zizugulavak.files.wordpress.com/2020/06/42012263501.pdf
    • https://bijetukexer.files.wordpress.com/2020/06/bitetemu.pdf
    • https://ketoseginosi.files.wordpress.com/2020/06/87406982140.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000064eb.bin
c027991dae24fe4fd985013c0189933cca36f66997ab28c61944fdc32502ac21
pdf-font-stream PDF embedded font (sfnt) at offset 0x64EB 11896 bytes