Malicious PDF — malware analysis report

Static analysis result for SHA-256 52e1d732beca4bb6…

MALICIOUS

PDF

46.1 KB Created: 2020-03-16 01:54:23 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 511d675d57cf829e6315c3cd234b24dd SHA-1: 85dd9acbfdc8185d80608b1e5156cf1fbc42b4cd SHA-256: 52e1d732beca4bb62f5987ad449f3556f22bd4be48f03f536f520ceed4dd8eab
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, a technique often used for SEO spam or to redirect users to malicious sites. The document body, though heavily obfuscated, contains references to 'ccproxy for windows server 2012' and metadata indicating it was generated by wkhtmltopdf, suggesting a lure for technical support or software-related scams. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://30nlr.bpmtc.com/uploads/1/3/0/5/130545199/130545199.html#ccproxy+for+windows+server+2012
    • http://meritcardmoapp.com/uploads/1/3/0/7/130739080/2684758.pdf
    • http://meetusanywhere.org/uploads/1/3/1/1/131163927/rutita_zupewepuvison.pdf
    • http://www.alexdanielski.com/uploads/1/3/1/1/131163737/3578311.pdf
    • http://homebenefitsavings.com/uploads/1/3/0/5/130551898/5662205.pdf
    • http://aoadigital.net/uploads/1/3/0/5/130590724/xupadijatej.pdf
    • http://mail.clubmakereurope.com/uploads/1/3/0/5/130551896/679d6a323814.pdf
    • http://eastbranchknives.com/uploads/1/3/0/4/130483043/molopejunuwumapax.pdf
    • http://www.fundacionsionaespiritu.com/uploads/1/3/0/6/130639774/3abd6fceb7e.pdf
    • http://bitterootmontana.com/uploads/1/3/0/3/130312916/57bf3e9c.pdf
    • http://www.oakridgevillage.net/uploads/1/3/0/3/130324288/jiligokazolem_danadogijajo_tuvudomed_feraw.pdf
    • http://www.greaterworkscenter.net/uploads/1/3/0/4/130436147/7bd6fe6311c02.pdf
    • http://artwithaplan.com/uploads/1/3/0/6/130639954/278a7c6b.pdf
    • http://nataliaestradaeditor.com/uploads/1/3/0/6/130604090/abae3f.pdf
    • http://elemenostudios.com/uploads/1/3/0/4/130476525/xagevi_kedumuz_pidelagat.pdf
    • http://crossfadeservices.com/uploads/1/3/0/4/130436085/popuxirubixumidisi.pdf
    • http://lincolnwayrealestatelawyer.com/uploads/1/3/0/8/130813381/b14d715f65a624.pdf
    • http://bpoconcierge.com/uploads/1/3/0/4/130476605/c7413.pdf
    • http://trueelegancetransportation.com/uploads/1/3/0/3/130323538/4038391.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000075bd.bin
61859966a5aea45c1a8129b2c3b0f52fa7dd4be78d56264a8e9aa3965adbbd63
pdf-font-stream PDF embedded font (sfnt) at offset 0x75BD 8296 bytes
font_01_sfnt_off000095e3.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x95E3 16036 bytes