Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9b313d87b668be0…

MALICIOUS

PDF

30.0 KB Created: 2020-05-13 13:50:06 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 8b32c64e8031383581ecfb968c0e06ad SHA-1: 64eff22ff53f903d3c17f561bf3d3a55a7580c87 SHA-256: f9b313d87b668be03567db186bd10b7913e7abd4eb6b7ec70092bf760e7d7efd
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was detected as a dropper by ClamAV. It contains a large number of external links, indicating it functions as a link farm. The primary purpose appears to be directing users to a multitude of other PDF files hosted on various domains, likely for SEO manipulation or to distribute further malicious content. The embedded URL also points to a similar structure.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Dropper.Agent-8272677-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-8272677-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://willowandsage.ca/uploads/1/3/0/7/130738501/130738501.html#latest+bollywood+movies++in+mp4
    • http://garageseo.com/uploads/1/3/0/4/130476083/1684972.pdf
    • http://breadchicago.com/uploads/1/3/0/6/130621859/jiloxetifub.pdf
    • http://zenlotusyoga.com/uploads/1/3/1/6/131636562/0468f521.pdf
    • http://cloudmamamagic.com/uploads/1/3/0/3/130323250/6587052.pdf
    • http://aw11source.com/uploads/1/3/0/5/130590535/kewoxadesosuxi.pdf
    • http://verybestgiftever.com/uploads/1/3/0/4/130488085/4e21b.pdf
    • http://healthatworkpartnership.com/uploads/1/3/1/4/131406722/dufokagadetona-notuvo.pdf
    • http://0205monshop.host/uploads/1/3/0/7/130738814/b4b78.pdf
    • http://wildmushroom.org/uploads/1/3/1/3/131398148/wumibuvuwew.pdf
    • http://aeweldingservices.com/uploads/1/3/0/7/130740465/fikotuderiro-suzujoregubuf-busal-vamaku.pdf
    • http://insearchofmaud.com/uploads/1/3/0/5/130539247/8664151.pdf
    • http://unidospor.net/uploads/1/3/0/5/130588597/5917715.pdf
    • http://richardbrunst.com/uploads/1/3/0/9/130969259/zenimene.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004cf6.bin
992525dbd9d7c2ef1271e7bc8fb7c3919e18860ae73b0ba4b0b36cfb9f09daad
pdf-font-stream PDF embedded font (sfnt) at offset 0x4CF6 9200 bytes