Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec29158e8139a9c1…

MALICIOUS

PDF

44.1 KB Created: 2020-04-27 18:44:00 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 95f50438e27498010c4516cec087d52e SHA-1: eebba7f7bf6cc0cf42d027622597f166ade8fda4 SHA-256: ec29158e8139a9c108bae71193e3f622292ce2dd407138a95196876443c66546
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, many with numeric slugs, indicating a link farm designed to host malicious content or redirect users to phishing sites. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this malicious intent. The document body, though heavily obfuscated, contains a URL that aligns with the findings of the heuristics.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wendellsamfordphotography.com/uploads/1/3/0/6/130639145/130639145.html#projected+balance+sheet+format+for+proprietor
    • http://morganelwell.net/uploads/1/3/0/3/130324092/zunig.pdf
    • http://back-to-wholeness.com/uploads/1/3/0/4/130483243/9901d50d5e.pdf
    • http://stage5investments.com/uploads/1/3/1/4/131437649/soxunotoxudi.pdf
    • http://icanwritethat.org/uploads/1/3/1/4/131454586/3171193.pdf
    • http://martipan.com/uploads/1/3/0/8/130874304/91361fc7b87cf6.pdf
    • http://lynettelewispsychologicalservices.com/uploads/1/3/1/6/131606228/1253a21688413.pdf
    • http://robinbladimir.org/uploads/1/3/1/4/131453136/zomumeramasoj_vabizemexon_lixukobuj_titokulovare.pdf
    • http://dumornay.org/uploads/1/3/0/8/130873998/687c58c07.pdf
    • http://rebeccapickens.com/uploads/1/3/0/3/130379145/loxus.pdf
    • http://binda-narine.com/uploads/1/3/0/9/130969704/4798767.pdf
    • http://passport2pain.com/uploads/1/3/0/7/130776590/e032a09a0e7144b.pdf
    • http://maizysstayandplay.com/uploads/1/3/0/6/130604637/nikokajajom_zazifafifupe_pexidevudagafe.pdf
    • http://yourxxtra.com/uploads/1/3/0/4/130483902/putikudenenupi.pdf
    • http://yourxxtra.com/uploads/1/3/0/4
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000080c8.bin
7db1cb3f6316c1b95024d9a6ddb4a10fec0daa4be6880bdf949f8f10284e915d
pdf-font-stream PDF embedded font (sfnt) at offset 0x80C8 8836 bytes