Malicious PDF — malware analysis report

Static analysis result for SHA-256 e60fa5f9ea3717b2…

MALICIOUS

PDF

122.0 KB Created: 2020-03-23 17:33:31 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 8ebbb55696025c901706eede73e8112a SHA-1: eff5a7bb03de93b722534aa710787891b3cb6cd2 SHA-256: e60fa5f9ea3717b2d9ebd4705279b246850088cc54b47ced68b46e13efed5297
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, a technique often used for SEO spam or to redirect users to malicious websites. The heuristic 'PDF_SEO_LINK_FARM' specifically flags this behavior, indicating a mass of external links pointing to domains like 'mgeducation.net'. While no scripts were extracted, the presence of numerous URLs suggests a delivery mechanism focused on external redirection.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://yogaandasianbodytherapy.com/uploads/1/3/0/7/130775186/130775186.html#anatomy+for+sculptors+understanding+the+human+figure
    • http://mgeducation.net/uploads/1/3/0/2/130289344/8338802.pdf
    • http://www.mct-training.nl/uploads/1/3/0/9/130969983/762974.pdf
    • http://blendedacademies.org/uploads/1/3/0/5/130550830/2486100.pdf
    • http://www.franciscoir.com/uploads/1/3/0/7/130776275/wexap-roxel-berulubiruzewoj.pdf
    • http://temescalpublicwitnessing.com/uploads/1/3/0/3/130323362/nasusudiwowi-zosemive-xanikaxezo.pdf
    • http://mta-sts.kisyoga.com/uploads/1/3/0/5/130588230/masin.pdf
    • http://www.wobbleandbass.co.uk/uploads/1/3/0/4/130435511/a71dc5c.pdf
    • http://themindtrainerhypnosis.com/uploads/1/3/0/6/130620776/9612313.pdf
    • http://lilbitofthisandthatstore.net/uploads/1/3/0/4/130435715/nikirokurebisesezu.pdf
    • http://maryrn.com/uploads/1/3/0/7/130739571/9277229.pdf
    • http://managedservicessacramento.support/uploads/1/3/0/7/130738824/5741171.pdf
    • http://cohenandriley.com/uploads/1/3/0/6/130620468/4a70d0bf745.pdf
    • http://flattaxidermy.net/uploads/1/3/0/5/130540296/puxer.pdf
    • http://mtdiablolandscaping.com/uploads/1/3/0/5/130551266/168245.pdf
    • http://ngravinggifts.shop/uploads/1/3/0/5/130539517/575833.pdf
    • http://www.katheezenn.com/uploads/1/3/0/4/130436207/koniwexanoliretexe.pdf
    • http://kaceyscloset.net/uploads/1/3/0/6/130604493/4003869.pdf
    • http://junetranmer.com/uploads/1/3/0/5/130588802/berot.pdf
    • http://atmdye.com/uploads/1/3/0/7/130776642/4744526.pdf
    • http://ms-holly-hagman.com/uploads/1/3/0/6/130639849/kunezafomuzin.pdf
    • http://prismassets.com/uploads/1/3/0/8/130813427/papusobuva-xibunej-vibetazenuf.pdf
    • http://oceanadvice.club/uploads/1/3/0/9/130969186/1617842.pdf
    • http://mydigitaldiva.net/uploads/1/3/0/6/130621852/voxifisiluwipezobu.pdf
    • http://ajhollowayministries.com/uploads/1/3/0/7/130775231/1164276.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001a0b1.bin
aaf7f93dd3d0812652ecf11986d6250e443d009bf93c929a2fd8d7123e39195d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A0B1 9236 bytes
font_01_sfnt_off0001c322.bin
08ab0a06935ac0e52a2b8408f6f933ecadd97e393ec35a968b9afe5e45bb7ca5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C322 16064 bytes