Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcc29f4df4e85f79…

MALICIOUS

PDF

37.6 KB Created: 2020-05-14 20:09:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 656a7a6bb2a8d23ca2fba1af225a86a5 SHA-1: f6670e5fcaa321364bf0e3ef4ac4d09962518f28 SHA-256: fcc29f4df4e85f79ce7e7e7124f714aa8f8187afbbc99a5774cf183ca20bae4e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, many pointing to other PDF files on various domains. This suggests a link farm or SEO manipulation tactic, or potentially a distribution mechanism for further malicious content. The document body text is largely garbled but contains a URL that matches one of the extracted links. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://alimeieryoga.com/uploads/1/3/1/3/131384791/131384791.html#printing+mailing+labels+from+google+sheets
    • http://mobilemechanicedinburgh.com/uploads/1/3/0/4/130489423/nemug.pdf
    • http://yuweipipes.com/uploads/1/3/1/4/131483090/dodam.pdf
    • http://tavernegoudenpunt.be/uploads/1/3/0/6/130604551/5678672.pdf
    • http://nghinspections.com/uploads/1/3/1/4/131455019/a115c4d964.pdf
    • http://zamticket.com/uploads/1/3/1/4/131406077/7b976.pdf
    • http://infinitytravellc.com/uploads/1/3/0/6/130639124/duzirejujaxazadoguwo.pdf
    • http://thewildwildweb.com/uploads/1/3/0/2/130288426/4292b36c2.pdf
    • http://spanish1withmravila.com/uploads/1/3/1/4/131437173/kogabuwuwo.pdf
    • http://margaritaroze.com/uploads/1/3/0/6/130620478/dalatiden.pdf
    • http://oceanbreezedentistrysf.com/uploads/1/3/1/3/131383981/192014.pdf
    • http://susiphotography.com/uploads/1/3/0/5/130589416/fuxilusiwag_mesuluzuliwis.pdf
    • http://app-pof.com/uploads/1/3/0/5/130588157/vanadud.pdf
    • http://jayshockblast.com/uploads/1/3/1/6/131637099/ruluvum.pdf
    • http://petitlapinbyjo.com/uploads/1/3/0/5/130589429/mupagorepesowobojim.pdf
    • http://nilsgebbers.de/uploads/1/3/0/5/130550785/f2958c0.pdf
    • http://cafedespecialitefrance.com/uploads/1/3/1/4/131406253/97908fc.pdf
    • http://earhartcorporatecenter.com/uploads/1/3/0/5/130588231/kobolitosot_zasomubup.pdf
    • http://annettesheavenlybreads.com/uploads/1/3/0/2/130272976/gunixusi-tujenekepevafu-korusofugug-kifofazovot.pdf
    • http://propedeuticatorino.com/uploads/1/3/0/6/130639659/pajonubufa_kefobofaj_dotujeb.pdf
    • http://djindyproductions.com/uploads/1/3/1/0/131071183/5366783.pdf
    • http://songproduction.com/uploads/1/3/0/6/130621362/823b40d901932a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006785.bin
29d6b9eebb738e2a78c8d536caca4b5db479d6e9a01368d5fa1169085e207153
pdf-font-stream PDF embedded font (sfnt) at offset 0x6785 10112 bytes