Malicious PDF — malware analysis report

Static analysis result for SHA-256 822890cc7e9cb321…

MALICIOUS

PDF

32.7 KB Created: 2020-04-07 03:46:47 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 50572e8458c255f698a4191e89ee7bc9 SHA-1: 4383c4cfb8bbeb52566008a9eec6a0b27e394680 SHA-256: 822890cc7e9cb32107d5f35f4d820fa5903f36332537e27f5e68cb2bac891cab
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which are hosted on newly created domains and use numeric slugs, indicative of a link farm or SEO poisoning tactic. The document body, though heavily obfuscated, contains text related to a 'maintenance kit lexmark ms810n' and references the URLs found in the heuristics. This suggests the document is designed to trick users into visiting malicious websites, likely for phishing or malware distribution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://digitalcard101.com/uploads/1/3/0/7/130740433/130740433.html#maintenance+kit+lexmark+ms810n
    • http://swkfrenchbulldogs.com/uploads/1/3/0/7/130739060/383feeb.pdf
    • http://beautyandwellness-bergkrichen.de/uploads/1/3/1/1/131163533/gilegufagir.pdf
    • http://fosrocindia.com/uploads/1/3/0/8/130814060/wuzerolokado.pdf
    • http://pbeventspr.net/uploads/1/3/0/7/130738998/luwiwejerutowofukos.pdf
    • http://edeni.shop/uploads/1/3/1/4/131453121/c834a1abe5e1f.pdf
    • http://rainbowsnoaz.com/uploads/1/3/0/7/130739419/8432249.pdf
    • http://themonhegangardener.com/uploads/1/3/0/3/130323212/b16ab62bf29c3ea.pdf
    • http://spitsquad.com/uploads/1/3/0/6/130621451/ratapofes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000056f7.bin
2881c8eaae113211fb88e80e5e0b6e329be257187bddf4f616d9e014678e1a0e
pdf-font-stream PDF embedded font (sfnt) at offset 0x56F7 8076 bytes