Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9d0ac3656adcd0e…

MALICIOUS

PDF

52.3 KB Created: 2020-03-29 15:27:59 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 82acbcab510aa56dda231f840b6fc761 SHA-1: dabc630e1fde9b0f843e6981b481de8692699b13 SHA-256: d9d0ac3656adcd0e45220ac0e625ebd3e0e69fb902b4af3e047a98b700347185
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains a mass external link farm, with 30 links pointing to various domains. The primary heuristic indicates a 'PDF_SEO_LINK_FARM' with a dominant host of 'sys-service.it'. The embedded document body text, though corrupted, contains a URL that matches the primary heuristic's target. This suggests the document is designed to drive traffic to a network of linked PDFs, likely for SEO manipulation or to distribute malware.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hotelvic-phase2-ja.devsite-1.com/uploads/1/3/0/8/130813934/130813934.html#que+es+paradigma+cualitativa+de+investigacion
    • http://sys-service.it/uploads/1/3/0/7/130738796/namikeruborixamaviz.pdf
    • http://myleansolutions.com/uploads/1/3/0/4/130476034/d430ed26c.pdf
    • http://gbcahill.com/uploads/1/3/0/5/130588286/1213ddf.pdf
    • http://rhymeswithlife.com/uploads/1/3/0/7/130775679/wajefofozovil.pdf
    • http://thefabdoctor.com/uploads/1/3/0/9/130969175/5765672.pdf
    • http://dermblog.com/uploads/1/3/0/3/130313434/63ea8.pdf
    • http://mytwinsister43023.com/uploads/1/3/0/2/130289693/pameri-nomuzofumiwoz.pdf
    • http://jacintaflt.com/uploads/1/3/0/7/130739067/a57027ca1c.pdf
    • http://hanniediner.com/uploads/1/3/0/5/130545485/098687f32eb2.pdf
    • http://progressideasandactions.org/uploads/1/3/0/6/130604824/4ebfcf027.pdf
    • http://vulturepeaksilverbars.com/uploads/1/3/0/3/130313188/zamifil.pdf
    • http://bordersoft.net/uploads/1/3/0/5/130590105/toledovitusivav_gogimosur.pdf
    • http://darkskytravel.com/uploads/1/3/0/6/130639385/lenezurejet.pdf
    • http://semabwa.com/uploads/1/3/0/2/130273573/bakos-titevunurujijin-debejado-sabugu.pdf
    • http://fangear.net/uploads/1/3/0/2/130289628/gepexepe_ruruj_gusudidiseli_mazovekefusi.pdf
    • http://homefirstconstruction.com/uploads/1/3/0/5/130543546/897df924ef.pdf
    • http://littletoncrabappletrail.org/uploads/1/3/0/9/130969658/41ba32.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a315.bin
1bc611582b85baa5eb8d4b171b55c82b7f2e6ed7b5fb79213c9c679495a2e70c
pdf-font-stream PDF embedded font (sfnt) at offset 0xA315 8844 bytes