Malicious PDF — malware analysis report

Static analysis result for SHA-256 1eb14cc861cf1e30…

MALICIOUS

PDF

39.3 KB Created: 2020-06-19 02:05:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5c23a0eb306b8c9fa8058e2c45aebe28 SHA-1: bb4a9258522a5ab29c362239148a2c61ed6e2c9f SHA-256: 1eb14cc861cf1e309b0c1ad02cec42d73637f4f502b89e36671d66bbebf6af0e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a large number of external links, many of which point to seemingly unrelated domains and are structured to appear as SEO content. The document body, though heavily obfuscated, contains references to 'Mcdonalds hockey cards price guide' and the authoring application, suggesting a lure to disguise the malicious intent. The primary attack pattern involves redirecting users to a link farm, likely to serve malicious content or phishing pages.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://staceysltd.com/uploads/1/3/0/3/130323236/130323236.html#mcdonalds+hockey+cards+price+guide
    • http://misscarolsartintheattic.com/uploads/1/3/0/2/130270946/3666b.pdf
    • http://hostmaster.happyteachers.co.uk/uploads/1/3/0/5/130552043/nowuko.pdf
    • http://74-123-73-225.mgwnet.com/uploads/1/3/0/4/130478868/wagaxi-vofefunog.pdf
    • http://tracybjorgan.ca/uploads/1/3/0/2/130273584/piwirovenem.pdf
    • http://mta-sts.impactgraphics.studio/uploads/1/3/0/7/130775021/d15a4368e5721d.pdf
    • http://svaakriti.com/uploads/1/3/0/6/130639626/kukojobasutavipu.pdf
    • http://germscd.com/uploads/1/3/0/4/130489172/9983630.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b39.bin
3c4dba6b4568087680a61dce6fed5c9a5c31c43b7e4502c1050f47a6ad2d51f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B39 5308 bytes
font_01_sfnt_off00006d38.bin
f6e699119e93f949c59c70fad87b4e6cd0fd4d1f56fca04fbd265930a553528d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D38 10636 bytes