Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e12b120efb52691…

MALICIOUS

PDF

29.8 KB Created: 2020-06-09 05:20:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 51795034d2745b64bdf6f457d33ae251 SHA-1: bcb5ad1edbc4c1b6eeffc4584d9d5a5766777c63 SHA-256: 4e12b120efb526915d4d4becc42cfd0c828bedb2033d79a619dece72eb120eb3
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, many of which point to other PDF files hosted on various domains. This behavior is indicative of a link farm or a redirection scheme designed to obscure the ultimate destination or to distribute malicious content. The document body text, while containing garbled characters, includes the phrase 'Video de reloj no marques las horas' and several URLs, reinforcing the idea of a lure. The heuristic 'PDF_SEO_LINK_FARM' strongly suggests this is an attempt to create a network of linked documents for SEO manipulation or to host further malicious content.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dunkhilldrygoods.com/uploads/1/3/0/4/130476587/130476587.html#video+de+reloj+no+marques+las+horas
    • http://repairdoctor.ca/uploads/1/3/0/4/130476844/suduzeg.pdf
    • http://zero22.org/uploads/1/3/0/6/130604564/wozozixenevaxeru.pdf
    • http://oakruninsurancesolutions.com/uploads/1/3/1/4/131407278/fokaxusekiwi.pdf
    • http://travel-in-vogue.com/uploads/1/3/0/4/130490410/ganekexezuxozi.pdf
    • http://smtp2.mangeprieaime.com/uploads/1/3/0/5/130588586/nadagirikuxeb-xonogozujepim-kezonefif.pdf
    • http://autodiscover.teambuildingidaho.com/uploads/1/3/0/6/130639824/sedotume.pdf
    • http://oneearly.com/uploads/1/3/0/6/130620620/genosi.pdf
    • http://foodsafetyprograms.org/uploads/1/3/0/3/130323249/471e88f8ea6.pdf
    • http://canadavisaoffice.net/uploads/1/3/0/3/130323255/9243537.pdf
    • https://zamomewa.files.wordpress.com/2020/06/21978093438.pdf
    • https://dupopopuf.files.wordpress.com/2020/06/jatonubapuwas.pdf
    • https://mudidakadeza.files.wordpress.com/2020/06/81229177967.pdf
    • https://jilorodi.files.wordpress.com/2020/06/lavabowuneradafesikuz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004907.bin
6415fe1fa8aeae7a426d35182561b6453784851e4ce58ce0bb824e724f5faada
pdf-font-stream PDF embedded font (sfnt) at offset 0x4907 10032 bytes