Malicious PDF — malware analysis report

Static analysis result for SHA-256 dac2310761ede242…

MALICIOUS

PDF

40.3 KB Created: 2020-04-01 18:21:15 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 71f4adc4b51e50e2fc5ed7d10907b57a SHA-1: 2edde3ba017dbb19c9844558981cc5262bbd1a29 SHA-256: dac2310761ede242a29166609500e82f9ee5f12ddd0cf966d2fb386138e16967
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO poisoning tactic. The document body, though partially corrupted, contains a reference to 'Glencoe geometry chapter 11 mid-chapter test answers', which may be a lure to attract unsuspecting users. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lancasterandhilton.com/uploads/1/3/0/8/130813577/130813577.html#glencoe+geometry+chapter+11+mid-chapter+test+answers
    • http://drrachelsfunctionalapproach.com/uploads/1/3/0/5/130589416/460e49ea39a91.pdf
    • http://knottahaybarn.com/uploads/1/3/0/5/130550936/vazanugareleze-tavewamunadum-budomug-kapedawuw.pdf
    • http://inforevit.com/uploads/1/3/0/7/130775498/3d69db118a.pdf
    • http://thetreesproject.org/uploads/1/3/0/6/130639197/2765948.pdf
    • http://kickout.eu/uploads/1/3/0/7/130739103/6813034.pdf
    • http://loyalcapitalinvestment.net/uploads/1/3/0/6/130639406/d5e17570ebc.pdf
    • http://bioxtreme.net/uploads/1/3/0/4/130492689/9219178.pdf
    • http://csmremodelingllc.com/uploads/1/3/0/2/130291724/tipadekikopugobov.pdf
    • http://treazuremebykitac.biz/uploads/1/3/0/2/130270843/561b14ee93ae.pdf
    • http://adriensaliba.com/uploads/1/3/0/8/130813458/rupifemo-bikis-zagesejiko.pdf
    • http://shopamysattic.net/uploads/1/3/0/2/130288768/rekaxitafudero-rirodezaletuk-pexofole-pokodum.pdf
    • http://laurenivey.com/uploads/1/3/0/9/130969143/53d60ad.pdf
    • http://danceintherain.us/uploads/1/3/0/2/130288861/woteziw_fonupa.pdf
    • http://frontporchbakingco.com/uploads/1/3/0/4/130483232/pazapap.pdf
    • http://lwilliamscounseling.com/uploads/1/3/0/5/130588931/4472973.pdf
    • http://sweetoccasions.info/uploads/1/3/0/5/130550838/7801397.pdf
    • http://overmedicating.com/uploads/1/3/0/7/130775012/3ac9f8d4507.pdf
    • http://fortheloveofcats.us/uploads/1/3/0/4/130489039/3e0ff4c2d7b7b.pdf
    • http://wizardart.online/uploads/1/3/0/6/130621859/pipapa.pdf
    • http://neurogastrolab.com/uploads/1/3/0/2/130273799/9169210.pdf
    • http://muslimahbasics.com/uploads/1/3/0/2/130289482/pesenile.pdf
    • http://changecricket.com/uploads/1/3/0/6/130605176/8710285.pdf
    • http://jordansgunworks.com/uploads/1/3/0/7/130776008/9798899.pdf
    • http://hallbartro.se/uploads/1/3/1/0/131069991/deratamoba_fapiz.pdf
    • http://theartofponcho.net/uploads/1/3/0/4/130490928/fa31e88.pdf
    • http://hallbartro.se/uploads/1/3/1/0/131
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000720a.bin
caf835994412a84efb9aabd473d3ef6c7294811c2a2ecc5053594783230088c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x720A 8568 bytes