Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5f1a06335df8952…

MALICIOUS

PDF

39.5 KB Created: 2020-03-30 07:41:37 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 0d6d0f6216b5bdfee79866fb7b2adb9d SHA-1: 4f269dca6c2a07ca2d63525c8db43a01cc5a1694 SHA-256: e5f1a06335df89520c5011afa1ece7efad084047279820f8199f4c3be28e226a
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document is identified as malicious due to a large number of embedded external links, characteristic of a link farm or SEO spam tactic. The document body, though partially corrupted, suggests a lure related to product instructions, potentially to disguise the malicious intent. The primary attack pattern involves directing users to a network of external PDF files hosted on various domains.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bernardobellostudio.com/uploads/1/3/0/4/130483848/130483848.html#hemnes+daybed+instructions+pdf
    • http://biponyclub.org/uploads/1/3/0/6/130620835/lotegolax.pdf
    • http://dappermaximusdesigns.com/uploads/1/3/0/6/130640021/gaxikupeli_topafafok_venal.pdf
    • http://jasperandpine.com/uploads/1/3/0/7/130739098/lasowovive_zixopezo.pdf
    • http://socialrealestateclub.com/uploads/1/3/0/6/130621084/7914026.pdf
    • http://naturalfest.net/uploads/1/3/0/3/130313249/vuwolav_ranuzofef.pdf
    • http://spyingheart.com/uploads/1/3/0/4/130476266/902971.pdf
    • http://harradvisors.com/uploads/1/3/0/5/130550974/cd181cc63f68.pdf
    • http://uhlenhof.eu/uploads/1/3/0/6/130605368/wusuxoduvip.pdf
    • http://mysweettopia.info/uploads/1/3/0/4/130488626/34a5c0e6.pdf
    • http://adreamed.net/uploads/1/3/0/5/130590399/4732307.pdf
    • http://studioviemen.com/uploads/1/3/0/8/130813381/74bf1a3ad03e2.pdf
    • http://makingmoneywithapps.com/uploads/1/3/0/2/130289333/toxibad.pdf
    • http://cgm2019.com/uploads/1/3/0/5/130588803/3252254.pdf
    • http://www.berlinartclass.com/uploads/1/3/0/7/130739158/zasotugu-padetevul-dutofo-fafasota.pdf
    • http://rapisend.com/uploads/1/3/1/1/131164382/fupimi.pdf
    • http://confidenceaesthetics.com/uploads/1/3/0/8/130873975/1913521.pdf
    • http://danielgraham.com/uploads/1/3/1/3/131380828/nasapidige-wuwego-lopikebone.pdf
    • http://sadgorilla.com/uploads/1/3/1/3/131379070/fejib.pdf
    • http://questessentials.com/uploads/1/3/0/5/130588810/659e488.pdf
    • http://stonefoxfeather.com/uploads/1/3/0/5/130544687/2319457.pdf
    • http://reeltherapyoman.com/uploads/1/3/0/5/130588728/jetamopifobogij.pdf
    • http://americanonesie.com/uploads/1/3/0/8/130873855/wonaxodogifutas-xozoz-dotosozuxuxuge.pdf
    • http://aussiecuddles.com/uploads/1/3/0/7/130775647/4683188.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000071a2.bin
b866feabf14a6764a9f2b4c275247e764463eb468b83ad4c056747cb84deefd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x71A2 7912 bytes