Malicious PDF — malware analysis report

Static analysis result for SHA-256 2125d9459f163a3c…

MALICIOUS

PDF

58.5 KB Created: 2020-03-25 02:18:39 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: fa0f2a7d2e462a3203b816697458a3b7 SHA-1: 923ed2eecd556309960d062dae4ad1ed597f8369 SHA-256: 2125d9459f163a3c816675cd0796c1919704596ff7faf6d3c513045606bd5a12
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document exhibits characteristics of an advance-fee scam, using lottery or prize language combined with parcel delivery requirements to deceive the user. It contains a large number of external links, many pointing to PDF files hosted on various domains, suggesting a link farm or redirection mechanism. One of the embedded URLs, http://kvconstruction.org/uploads/1/3/0/3/130312965/130312965.html#ansys+ls+dyna+download, is likely intended to trick the user into downloading a malicious file.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kvconstruction.org/uploads/1/3/0/3/130312965/130312965.html#ansys+ls+dyna+download
    • http://coinspacespain.com/uploads/1/3/0/3/130313463/xenulelalo-judusolevefedad-tesafodok.pdf
    • http://www.elixirholistictherapy.com/uploads/1/3/0/3/130323743/b0dab9f.pdf
    • http://www.snorkelx.com.au/uploads/1/3/0/8/130873794/tavarafupojafelemiz.pdf
    • http://bolton-nursery.org.uk/uploads/1/3/0/5/130551054/635ed21da2765e7.pdf
    • http://www.nextstepsoberliving.org/uploads/1/3/0/6/130621425/wutetevowa.pdf
    • http://reporteswtw.com/uploads/1/3/0/6/130639682/4853421.pdf
    • http://vlgphotography.com/uploads/1/3/0/5/130550756/4490452.pdf
    • http://majesticcabinetsinc.com/uploads/1/3/1/1/131163737/jotuver_kalife.pdf
    • http://nashobavalleyextractco.com/uploads/1/3/0/5/130541208/luzowu-letijol-furojitep-lewuwerudede.pdf
    • http://amyephdcmsp.com/uploads/1/3/0/6/130620194/89c3d437dc579.pdf
    • http://thecapehomerepair.com/uploads/1/3/0/2/130271157/8476116.pdf
    • http://www.whatthefunkdenver.com/uploads/1/3/0/2/130287243/digibiga.pdf
    • http://malolokids.com/uploads/1/3/0/4/130476215/lemofosomokumo-baxam-piwulibuxap-xesij.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bd07.bin
f02dd435f4ac33e1b0603efc375bccc1e3dfea3f8be6954f4f262ea1ded5e3cc
pdf-font-stream PDF embedded font (sfnt) at offset 0xBD07 8260 bytes