Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7e46f3bf990119e…

MALICIOUS

PDF

33.7 KB Created: 2020-04-20 22:40:06 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 8d3cd596a3867e26d25cc4e561766a48 SHA-1: 972c9a040dc5e9833f55ff720d12569837034a8d SHA-256: e7e46f3bf990119e4612b8b0646f8228ee37fe9a3dc9d0b19348671a362acfba
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains numerous external links, a common tactic for SEO poisoning and directing users to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, suggesting a link farm designed to manipulate search engine results. The document body, though partially corrupted, contains text related to 'Peptic ulcer guideline 2018', likely a lure to disguise the malicious intent. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://olallagreens.biz/uploads/1/3/1/3/131397942/131397942.html#peptic+ulcer+guideline+2018+%E0%B9%84%E0%B8%97%E0%B8%A2
    • http://ellischangeconsulting.com/uploads/1/3/0/8/130813037/114483.pdf
    • http://sheplaysstrong.com/uploads/1/3/0/7/130776646/pujomutilubimi-taponejibe.pdf
    • http://rmfutbolusa.com/uploads/1/3/0/6/130604766/wirunewu.pdf
    • http://heatwaveheadware.com/uploads/1/3/0/4/130435578/223866.pdf
    • http://margoforward1.com/uploads/1/3/1/1/131164394/184325.pdf
    • http://familiadiesa.com/uploads/1/3/0/6/130639946/4109f.pdf
    • http://alitebiomedical.com/uploads/1/3/1/3/131383323/dufatuxaz.pdf
    • http://timnorris123.com/uploads/1/3/1/3/131379541/zugirimamiba-dosonexiw.pdf