Malicious PDF — malware analysis report

Static analysis result for SHA-256 51cdf387179cc763…

MALICIOUS

PDF

19.6 KB Created: 2020-06-22 02:50:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 60f75dd3dd6250d9d4790d62b22ab12d SHA-1: 8b860955ca238bece584331f7b70fd86fa01c806 SHA-256: 51cdf387179cc763951abc891d9e373ed920b6cd74ed6c8d7fd6531d8dbc34f2
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external URLs, identified by the PDF_SEO_LINK_FARM heuristic. These URLs point to various domains, suggesting a link farm or a distribution mechanism for malicious content. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery or execution methods. The primary attack pattern observed is the mass distribution of links within the document.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://webdisk.choisnuts.com/uploads/1/3/0/5/130589180/130589180.html#command+prompt+tricks+pdf
    • http://mx.jolinng.com/uploads/1/3/0/7/130775984/9b8bb391f540.pdf
    • http://uaeara.com/uploads/1/3/0/7/130775376/tunowewuragukos-gabuzuwavo-mabadudinofi-piwivatabiratam.pdf
    • http://jeanettesjoberg.com/uploads/1/3/0/7/130738850/1151213.pdf
    • http://ecuriebarnton.com/uploads/1/3/0/7/130739260/7088533.pdf
    • http://mail.houseofdiamondsart.com/uploads/1/3/0/5/130589238/b0a9d1af108bccc.pdf
    • http://quality-cert.com/uploads/1/3/0/9/130969532/51e618ef08.pdf
    • http://ellenslight.com/uploads/1/3/1/3/131379247/6726508.pdf