Malicious PDF — malware analysis report

Static analysis result for SHA-256 eaf109522fe58820…

MALICIOUS

PDF

47.3 KB Created: 2020-04-01 13:24:32 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 76c26de6e90edc4ab0d69a2f01210ab5 SHA-1: 78dbecbb6182edd531283d391353144ae54ef827 SHA-256: eaf109522fe588207c6f777b93f6fec0009f8362ac2355f9d926a6bbf7320df1
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or distribution network. The document body, though partially corrupted, contains the title 'Ejemplos palancas de segundo genero' and references to wkhtmltopdf, indicating it was likely generated programmatically. The primary purpose appears to be directing users to a large number of external resources, potentially for SEO manipulation or to serve as a landing page for further malicious activity.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://seasonalshowers.com/uploads/1/3/0/5/130543045/130543045.html#ejemplos+palancas+de+segundo+genero
    • http://biding-my-time.com/uploads/1/3/0/4/130476684/8717688.pdf
    • http://threemodernpearls.com/uploads/1/3/0/4/130476050/daridobuli.pdf
    • http://kaslou.shop/uploads/1/3/0/5/130541765/vujadazigoga-rajedejijasu-jurodot-numovokagu.pdf
    • http://kcbevco.com/uploads/1/3/0/6/130620431/2905973.pdf
    • http://scottmsiegel.com/uploads/1/3/0/5/130551463/kitamo-dokuke-fagexeg-ximepuzaga.pdf
    • http://milltowngrille.com/uploads/1/3/0/5/130588480/varas_powumixez_xaparusoxas_bubebalebadawop.pdf
    • http://kimblynehenrydesigns.com/uploads/1/3/0/9/130969725/f254f8c.pdf
    • http://joywyangpassword.com/uploads/1/3/1/3/131380894/vafomitibuz.pdf
    • http://internaddict.com/uploads/1/3/0/9/130969833/sivipapa.pdf
    • http://lionsclub5k.com/uploads/1/3/0/6/130605001/wonijuroturo.pdf
    • http://barriebasketball.com/uploads/1/3/0/3/130312926/menevufozunubofoluxi.pdf
    • http://nxlevelphysicaltherapy.com/uploads/1/3/0/8/130813554/kogukujigod-rafudemaneruja.pdf
    • http://crushinator.com/uploads/1/3/0/6/130640231/pokatixame-zinakotuna-tusiga.pdf
    • http://chaoscleaners.com/uploads/1/3/0/2/130270898/fomizal-konopapu-tirisalidejogoz.pdf
    • http://comtypsi.com/uploads/1/3/0/4/130435581/kapuzutixa.pdf
    • http://spinstersguidetodating.com/uploads/1/3/0/8/130813768/272f15a385d.pdf
    • http://roadweasles.com/uploads/1/3/0/4/130436365/larojisoworet.pdf
    • http://simplynature-fineartphotography.com/uploads/1/3/0/6/130621277/9122933.pdf
    • http://dhoffmanandassociates.com/uploads/1/3/0/4/130477193/2339a888e260.pdf
    • http://irstranscript.com/uploads/1/3/0/6/130621596/kawuza.pdf
    • http://furrysmithlaw.com/uploads/1/3/0/7/130738596/a0153201.pdf
    • http://overdriveart.it/uploads/1/3/0/5/130552034/be4d4a5.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073b1.bin
46ece2d8b825a70675e3634eeceed8e008e45280cea7f916bd14fa6b7f73c42a
pdf-font-stream PDF embedded font (sfnt) at offset 0x73B1 8904 bytes
font_01_sfnt_off00009419.bin
ba8450af9defeecc4b8fb4e5ed11065773f6da0e38050667c4a0aff436bdb49f
pdf-font-stream PDF embedded font (sfnt) at offset 0x9419 17232 bytes