Malicious PDF — malware analysis report

Static analysis result for SHA-256 a192ee424ebe43c7…

MALICIOUS

PDF

49.6 KB Created: 2020-04-06 09:19:04 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 8bc94fa9220f23f4a776c57d29e797ef SHA-1: ce7223e0a09a4a2681aaae7d0f6cab4cb5dfef20 SHA-256: a192ee424ebe43c7bbfd7b170cc61678ffa0ffef64dc4336037e17c604d5dc2e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The document body also contains a prominent URL, 'http://blockchainambassador.ca/uploads/1/3/1/3/131379409/131379409.html#john+douglas+mindhunter+quotes', which is part of this link farm. The primary purpose appears to be directing users to a wide array of other PDF documents hosted on unrelated domains, likely for malicious distribution or SEO spam.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://blockchainambassador.ca/uploads/1/3/1/3/131379409/131379409.html#john+douglas+mindhunter+quotes
    • http://sirwilliamlandscaping.com/uploads/1/3/0/4/130483384/f2f6e663361.pdf
    • http://twistedsugarut.com/uploads/1/3/0/7/130739648/gizupu.pdf
    • http://resource-agencies.eu/uploads/1/3/0/4/130436415/zigonaxejo.pdf
    • http://myurbanhermit.com/uploads/1/3/0/5/130551186/4035336.pdf
    • http://alexmcmichael.com/uploads/1/3/1/4/131454496/nabazesebasopi.pdf
    • http://ecodiamondclean.com/uploads/1/3/0/6/130620565/dudexixub.pdf
    • http://revolutionaryimprints.com/uploads/1/3/1/3/131398412/keloz-kosatifekefa-wosusejoganiku.pdf
    • http://assetskill.com/uploads/1/3/0/6/130620471/2345926.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000088ef.bin
45d75015d00fd711b96a099742cbd043804fd9953db21d434c6b55a7a5f1ebdc
pdf-font-stream PDF embedded font (sfnt) at offset 0x88EF 11968 bytes
font_01_sfnt_off0000b052.bin
87fd6b1a35a64f5c2d30902eea89631a9c05d6b36ef70c6d0cee4d2ad867525e
pdf-font-stream PDF embedded font (sfnt) at offset 0xB052 2596 bytes