Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4f35ba038e275e0…

MALICIOUS

PDF

34.0 KB Created: 2020-03-29 11:26:08 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 4d2505258018772692934df6ff8e6924 SHA-1: 7c050f7be99c3967b8ba0418d5adaa913f3dc161 SHA-256: e4f35ba038e275e01d7f8bdfa41390b80051869c96973f8275e79b3ab02e2bb0
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to similarly structured URLs on different domains. The document body text, while partially obfuscated, includes a reference to 'Guion de noticias tv azteca en vivo hoy', suggesting a lure to news content. The primary heuristic indicates a 'PDF_SEO_LINK_FARM', suggesting the document is designed to generate traffic or distribute links to a large number of external sites, likely for SEO manipulation or to host further malicious content. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://woodlandstuition.com/uploads/1/3/0/3/130313702/130313702.html#guion+de+noticias+tv+azteca+en+vivo+hoy
    • http://schoenapartments.com/uploads/1/3/0/3/130379096/gazisaxegaliv-tekin-radazekujowa.pdf
    • http://nerf-battle-party.com/uploads/1/3/0/6/130621721/berulutotozur.pdf
    • http://alittlebitofeverything24.com/uploads/1/3/0/7/130739510/rutapoganilegok_podewaronuvug_kewolobexeso.pdf
    • http://pinehavenfamilyday.com/uploads/1/3/0/4/130490250/wurafigul-zolek-zulonavuruzedos-fozefad.pdf
    • http://ngbeautymakeupstore.com/uploads/1/3/0/7/130776804/d971b22bc8a.pdf
    • http://rrleads.ca/uploads/1/3/0/5/130589166/majobukexozonik.pdf
    • http://i-airconditioning.com/uploads/1/3/0/5/130546000/4261176.pdf
    • http://hartmanconstruction.net/uploads/1/3/0/5/130589171/zoxeros.pdf
    • http://shopmazanis.com/uploads/1/3/0/4/130488699/52cd0e4efc664b.pdf
    • http://peakvistafoundation.org/uploads/1/3/0/6/130639500/rakinom.pdf
    • http://webdisk.surfsidesportsweargifts.com/uploads/1/3/0/6/130604701/6893418.pdf
    • http://gtlaw.net/uploads/1/3/0/9/130969809/tefiwulobusuvu_zexageka.pdf
    • http://valssalon.com/uploads/1/3/0/5/130543333/jodoj.pdf
    • http://bakingdata.com/uploads/1/3/0/5/130588983/mawuludo_sufawumosune.pdf
    • http://mandaladreamco.com/uploads/1/3/0/5/130551279/04bd11165050bc6.pdf
    • http://bainversion.com/uploads/1/3/0/3/130313306/abb3e6065.pdf
    • http://jurongdistrict22.com/uploads/1/3/0/5/130588805/1963290.pdf
    • http://pinhoti100.com/uploads/1/3/0/6/130604533/3722384.pdf
    • http://richoffinvestments.com/uploads/1/3/0/6/130605490/povomufagujor_sadusu.pdf
    • http://adisera.com/uploads/1/3/0/5/130541103/5041014.pdf
    • http://zumbawithdenisenyc.com/uploads/1/3/0/3/130313324/mapani.pdf
    • http://sophiamason.org/uploads/1/3/0/8/130814055/6964614.pdf
    • http://earthworkzseptic.com/uploads/1/3/0/2/130291463/3764747.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005cc5.bin
b018e18a026e62b152400271a3bfc560c17225b9ed32120c73f80bb06f9dec8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CC5 6988 bytes