Malicious PDF — malware analysis report

Static analysis result for SHA-256 e293e933ed56069f…

MALICIOUS

PDF

49.3 KB Created: 2020-03-24 13:24:34 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 51ae91c70c3832f550fa8999dba93815 SHA-1: 8093f6df631d8287493e1fcbf9137d82e12a1702 SHA-256: e293e933ed56069fb0672b46c2840a378848d0f60f103faeec5330373653da5e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO manipulation tactic. The embedded URLs are likely intended to redirect users to potentially malicious content or phishing sites. No scripts were extracted, limiting the analysis of direct execution capabilities.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getplantpower.com/uploads/1/3/0/3/130313193/130313193.html#experimento+deterministico+y+aleatorio
    • http://www.jonasfarmholidaybarns.co.uk/uploads/1/3/0/6/130621404/3d76332e6.pdf
    • http://dogfriendlyphx.com/uploads/1/3/0/8/130874652/venozerunese-givupakelel-xanop-gojagibebomape.pdf
    • http://glitster.com/uploads/1/3/0/3/130323362/604a49d.pdf
    • http://dog-friendly.org/uploads/1/3/0/5/130588268/wujuxin.pdf
    • http://www.twoglasses04.com/uploads/1/3/0/6/130604429/zemobesunofun-sefuz.pdf
    • http://chinagardenct.com/uploads/1/3/0/5/130545333/8507990.pdf
    • http://kandeladesigns.com/uploads/1/3/0/7/130775085/bezevemizo-wibavekivokuk-surir.pdf
    • http://ageless-wellbeing.com/uploads/1/3/0/8/130813307/cc168ded347.pdf
    • http://solveput.com/uploads/1/3/0/6/130621973/nufiforul-zakuriz.pdf
    • http://cabinaselshaddai.com/uploads/1/3/0/6/130639734/xabazajarovuloruwip.pdf
    • http://fosterkittykamp.com/uploads/1/3/0/3/130379798/sevaba_weroza.pdf
    • http://my.trssociety.ca/uploads/1/3/0/5/130551401/talepi-bonekepupinaro-janowod-bupigojumural.pdf
    • http://kadampa.club/uploads/1/3/0/6/130604640/60ccc4e631c0e1c.pdf
    • http://hostmaster.sugartrampoline.co.uk/uploads/1/3/0/5/130588512/a0a0077ae916.pdf
    • http://milliondollarlooks.net/uploads/1/3/0/7/130738646/xodejonedoselig.pdf
    • http://www.folkestoneantiquescollectables.co.uk/uploads/1/3/0/6/130639521/3618841.pdf
    • http://sparzug.com/uploads/1/3/0/2/130272083/bediruveladib_fosematuwufapa_jenili_giwuwufiwi.pdf
    • http://busybossfit.com/uploads/1/3/0/5/130589389/wutuvasonanoku.pdf
    • http://majordrillling.com/uploads/1/3/0/6/130604896/pojiwezu-gebejuvatok-vugufexumupina.pdf
    • http://www.precisionconcretemi.com/uploads/1/3/0/6/130620348/28cb08.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000072dc.bin
4a7ff3c20d1b15e415b14de7091ae8453af56693e232f6fb2cd03e2b535230ad
pdf-font-stream PDF embedded font (sfnt) at offset 0x72DC 10268 bytes
font_01_sfnt_off000095af.bin
940d2c98d9fc32a4b27d5eb39100a2b30c1c214c0ede3631f444561a3409f4f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x95AF 2964 bytes
font_02_sfnt_off0000a038.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0xA038 16036 bytes