Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfedc871c91a2d56…

MALICIOUS

PDF

69.0 KB Created: 2020-05-25 07:14:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5d2115e94fddbba97084c51a56cb54f3 SHA-1: bf580c4cb6dc4f618f13e0b9871ae482e58c789c SHA-256: cfedc871c91a2d560320a5665f8a18d2c2687bbb900c74c62722f12fe2776162
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, a technique often used for SEO spam or to redirect users to malicious websites. The heuristic 'PDF_SEO_LINK_FARM' specifically flags this behavior, indicating a potential for malicious redirection. No scripts were extracted, limiting further analysis of direct payload delivery.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://family-enterprises-llc.com/uploads/1/3/0/4/130476859/130476859.html#introductory+statistics+gould+2nd+edition+pdf
    • http://legacyremodeling.net/uploads/1/3/1/8/131857631/4292762.pdf
    • http://ravetampa.com/uploads/1/3/0/3/130323392/zemixowozipi.pdf
    • http://blackdampbrewing.com/uploads/1/3/1/6/131637876/tapifaxe.pdf
    • http://blog.besimplytimeless.com/uploads/1/3/1/0/131071033/e4db3.pdf
    • http://granvilleislandfoodiebox.com/uploads/1/3/1/8/131856270/7239754.pdf
    • http://joannhughes.com/uploads/1/3/0/2/130271185/xinekaxewibexikoxif.pdf
    • http://industrialcommercialdomestic.com/uploads/1/3/1/6/131637219/fatesezo.pdf
    • http://host197.carmichaelnl.com/uploads/1/3/0/7/130776858/wajij.pdf
    • http://caravanadelamor.com/uploads/1/3/1/3/131379749/39e010f1.pdf
    • http://black-ventures.com/uploads/1/3/1/0/131070521/2d8daec11aba.pdf
    • http://christinesastri.com/uploads/1/3/0/7/130740252/penipugu.pdf
    • http://booksbybrucepierce.com/uploads/1/3/1/4/131413550/5852284.pdf
    • http://qspandp.com/uploads/1/3/0/6/130621337/dunopowerenibu_bigetewakidixe.pdf
    • http://malloyirishdanceschool.com/uploads/1/3/0/6/130605312/lalajososezijupiv.pdf
    • http://supportparentsg.com/uploads/1/3/1/4/131454051/f90ba7bf.pdf
    • http://tiffinsfromhome.com/uploads/1/3/0/5/130589057/0d93c27420dae8f.pdf
    • http://commediaprod.com/uploads/1/3/1/6/131636852/lejedajevomiz_pawojusalomege_kagegijazoga_tulaboxavaxarup.pdf
    • http://meganccwalker.com/uploads/1/3/1/3/131383892/gubesar.pdf
    • http://rebeccaharrisbooks.com/uploads/1/3/0/5/130539203/5908148.pdf
    • http://bandician.club/uploads/1/3/0/4/130483527/koxoxamugokarad_vuzatununusos_judabadokalob_fobawedaxifotef.pdf
    • http://alearnersheart.org/uploads/1/3/1/6/131637384/dukel.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dff5.bin
d7e54b6f8d5d0d372bc5e6cf507858dd7dfdccc96b0881b02fae8dadc2c93e23
pdf-font-stream PDF embedded font (sfnt) at offset 0xDFF5 11032 bytes