Malicious PDF — malware analysis report

Static analysis result for SHA-256 d244715cda39ac08…

MALICIOUS

PDF

39.8 KB Created: 2020-04-04 09:30:48 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 46ca800fa126371496534404b462a605 SHA-1: 09dd183640eb77689785696e51469586ee983cb8 SHA-256: d244715cda39ac089f98b69fca83f2246f27f1ac67f34001e66a8c8ff3c51597
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains a significant number of external links, identified as a PDF SEO link farm. The document body, though heavily obfuscated, contains references to URLs that are part of this link farm. This suggests the primary purpose is to direct users to potentially malicious or SEO-abused external sites.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bejustalittlebetter.com/uploads/1/3/0/7/130740465/130740465.html#convert+double+to+float+matlab
    • http://vailskishuttle.com/uploads/1/3/0/6/130639073/guper.pdf
    • http://markitech.net/uploads/1/3/0/4/130483864/3997097.pdf
    • http://andrewkincaidllc.com/uploads/1/3/0/4/130488101/bdf641828b.pdf
    • http://quiltandopatchwork.com/uploads/1/3/0/8/130813642/1cb2b32b46.pdf
    • http://alaskakarate.org/uploads/1/3/0/4/130483912/vasitukesol.pdf
    • http://banriapharma.com/uploads/1/3/0/6/130621465/744155.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000068d0.bin
6bdc4d9965432e94d6304d580c7dfefabd2e8d5dab53d0349acc204bc57c3490
pdf-font-stream PDF embedded font (sfnt) at offset 0x68D0 8208 bytes
font_01_sfnt_off00008894.bin
985cbd9ba5b629f1b749d04d852c0eecb5d8ad374186a1044a60da9476420dc6
pdf-font-stream PDF embedded font (sfnt) at offset 0x8894 2788 bytes