Malicious PDF — malware analysis report

Static analysis result for SHA-256 e6d22c427b35205b…

MALICIOUS

PDF

36.5 KB Created: 2020-05-17 22:17:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3a35635167f34748fff1b4862851835e SHA-1: bd98f5213cae4b55e6a6bb209c1646a7b7af14f4 SHA-256: e6d22c427b35205b3387f6a99219bba993697555de408d05eeb0b60285553477
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded external links, a technique often used for SEO poisoning or to redirect users to malicious content. The document body, though partially corrupted, suggests a lure related to an 'apartment lease agreement'. The primary heuristic identified a link farm hosted on 'apptester.site', indicating a likely attempt to drive traffic to potentially malicious or phishing sites. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://directorsofficersliabilityinsurance.wales/uploads/1/3/0/3/130313590/130313590.html#apartment+lease+agreement+word+format
    • http://apptester.site/uploads/1/3/0/4/130483318/5963412.pdf
    • http://ingarundquist.com/uploads/1/3/1/3/131379398/929bb56939883d.pdf
    • http://trelyongallery.com/uploads/1/3/1/8/131871622/9c7ad0e7782c.pdf
    • http://lexihermistondestinationweddings.com/uploads/1/3/0/8/130814933/6e09d5da.pdf
    • http://greenlogy.org/uploads/1/3/1/1/131164573/mudepuda.pdf
    • http://bulliednomore.ca/uploads/1/3/0/6/130621354/2c52f0d9eea.pdf
    • http://pof-callapp.com/uploads/1/3/1/1/131164456/2dbc2eccf1b450.pdf
    • http://3767worsham.com/uploads/1/3/0/6/130639581/972297b0c3ba1.pdf
    • http://ethnish.com/uploads/1/3/0/6/130621663/2751605.pdf
    • http://carlisletitlemarketing.com/uploads/1/3/0/6/130639943/fifufujafoliduj-kasiketa-kixasozep-doperotozosu.pdf
    • http://gimmeforevershelter.org/uploads/1/3/0/6/130605165/wejijem_setenipunomon_pimotukasi.pdf
    • http://300productions.com/uploads/1/3/1/4/131406806/bijuwoder_wiwasolufupegeb.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006312.bin
09ea177462daf6c6cf6d0a7126cd2bb67cf0446431eaf733fa75c4400160e74e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6312 10552 bytes