Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3dea041304d2f7d…

MALICIOUS

PDF

40.3 KB Created: 2020-04-07 12:47:12 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 756952916a8f8d501584e975ec201bd2 SHA-1: 8ae904043765c4410dcb379b8d6782edda4e9ac7 SHA-256: f3dea041304d2f7d284f598f0cf6c7ab86c6f7ef71fe8f910bc0b9b004685fc9
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which appear to be part of an SEO link farm. The document body, though partially corrupted, includes a URL that also points to an external HTML file. This suggests the primary intent is to redirect users to potentially malicious websites, possibly for phishing or malware distribution. No scripts were extracted, limiting the ability to determine further payload execution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://juliejesternewman.com/uploads/1/3/0/7/130739935/130739935.html#saludos+formales+e+informales+en+ingles+y+su+pronunciacion
    • http://journey-woman.com/uploads/1/3/0/2/130287413/9326529.pdf
    • http://justbreathelifecoach.com/uploads/1/3/0/6/130605116/2090566.pdf
    • http://gicato-sucu.com/uploads/1/3/1/4/131437616/e9977f1b2732.pdf
    • http://southwestfloridacbd.com/uploads/1/3/0/8/130814636/jipalalazumavaxiguk.pdf
    • http://accountcontrolfoundation.org/uploads/1/3/0/2/130289813/meruxafovebo-toborev-sebuxikudebob.pdf
    • http://springhillsupplyltd.com/uploads/1/3/0/6/130621524/fategazoturofigevazu.pdf
    • http://pogopossum.net/uploads/1/3/1/1/131164136/c68a38d0782d.pdf
    • http://shopkennebunkmaine.com/uploads/1/3/0/8/130874113/bilubovibil-jufubegenov.pdf
    • http://plumluvfoods.com/uploads/1/3/0/6/130620479/judijodatano.pdf
    • http://gep-global.com/uploads/1/3/0/6/130603740/nonasamesitalepe.pdf
    • http://shootingrobots.com/uploads/1/3/0/5/130550955/8349421.pdf
    • http://emilyswinford.com/uploads/1/3/0/7/130775748/xegejedef-xezanamavesikif-wakazaji-regak.pdf
    • http://financejobdescriptions.com/uploads/1/3/1/3/131380438/9606848.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007151.bin
17cb5bc39831e892e993fa974f57a1d9ab6acc21348d39d336060bd367d4ab80
pdf-font-stream PDF embedded font (sfnt) at offset 0x7151 8940 bytes