Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8a1f12ad0828204…

MALICIOUS

PDF

39.0 KB Created: 2020-04-06 07:43:41 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 57cd93924f5383b0d31a041f1bbb452a SHA-1: 6e76f91a1e7377e1295415ee4846127ac54facca SHA-256: e8a1f12ad08282041f28c6f4e96d59e3016a358b086475a598d009d83e9e2e63
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to PDF files with numeric slugs, a common SEO spam technique. The document body, though partially corrupted, contains a title related to chemical reactions and includes the same URLs found in the heuristics. This suggests the document is designed to drive traffic to these external sites, likely for SEO manipulation or to host malicious content.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://redheadmunchiesgourmetsnack.com/uploads/1/3/0/3/130323212/130323212.html#como+hacer+una+reaccion+quimica+casera
    • http://streamlineevents.net/uploads/1/3/0/7/130774970/8498268.pdf
    • http://1schoolsystem.com/uploads/1/3/0/4/130477890/114f073cce.pdf
    • http://talkingclips.org/uploads/1/3/0/5/130590200/majonovunikofili.pdf
    • http://isakkdesign.com/uploads/1/3/1/3/131398543/aa4945d85.pdf
    • http://sevenamericanbistro.com/uploads/1/3/1/1/131164564/9c9ad34a611.pdf
    • http://sureprize.net/uploads/1/3/0/2/130272577/10ef56bc76.pdf
    • http://jluabc.com/uploads/1/3/0/5/130551230/nemutoribozuja.pdf
    • http://industrialchanginglandscape.com/uploads/1/3/1/4/131438155/c70179.pdf
    • http://corcoranbottleshop.com/uploads/1/3/0/2/130272319/2265724.pdf
    • http://sophiashair.com/uploads/1/3/1/4/131452821/e0acb.pdf
    • http://theouterlookinc.com/uploads/1/3/0/5/130545753/dd8e33.pdf
    • http://carolinaeast.ca/uploads/1/3/0/7/130739280/9557321.pdf
    • http://partssolution.co/uploads/1/3/0/4/130490776/7107087.pdf
    • http://danskasfalt.com/uploads/1/3/1/3/131398583/3667413.pdf
    • http://easilyoffendedtissuehat.com/uploads/1/3/0/7/130739052/34086caf3eb78cb.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f15.bin
55e03eee0390aa53630c5581911e129ceac56d73d5c44ac3fec2d0c76a6f8fb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F15 8848 bytes