Malicious PDF — malware analysis report

Static analysis result for SHA-256 acae6b93dc1afab3…

MALICIOUS

PDF

55.8 KB Created: 2020-04-17 04:50:26 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 6431bb428ec15e92fe9903eadf99fb74 SHA-1: d86b6baeb1f11e8e7909fc4f75ebeb3387536324 SHA-256: acae6b93dc1afab33aa5c104c9008ce8cbf483d3123c5aee0b10cd6d9b6bd2d4
62 Risk Score

Malware Insights

MITRE ATT&CK
T1598 Gather Victim Identity Information T1204 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO manipulation tactic. The embedded URL heuristic also fired, indicating the presence of external links within the document body. The primary goal appears to be directing users to a network of external PDF files, potentially for distributing malware or for SEO spam.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mkemanagement.com/uploads/1/3/0/6/130639445/130639445.html#reporters+without+borders+usa
    • http://giant-hearts.com/uploads/1/3/0/7/130775965/f917e.pdf
    • http://danceinapuddle.com/uploads/1/3/0/6/130620852/7188605.pdf
    • http://ldeleon.net/uploads/1/3/1/4/131407395/3318515.pdf
    • http://firemarkinspections.com/uploads/1/3/0/8/130814066/6627180.pdf
    • http://pictakerr.com/uploads/1/3/0/9/130969645/padebike_xomorigibob_morolewan.pdf
    • http://plumbingsystems.org/uploads/1/3/0/5/130546486/95db95a.pdf
    • http://hayes-construction-andson.com/uploads/1/3/0/7/130775540/650575.pdf
    • http://stefanbrewer.com/uploads/1/3/0/2/130271124/lazezibusufatudetu.pdf
    • http://appleb.org/uploads/1/3/0/9/130968997/d84d9768d0.pdf
    • http://care-giving.com/uploads/1/3/0/7/130775379/5cc482a03312f3b.pdf
    • http://marc-renaud.ch/uploads/1/3/1/4/131454034/7c1d4835720b007.pdf
    • http://rama-dasa.com/uploads/1/3/0/6/130621351/gigafik_rawamomizep_padefoteravo_lorazifuwapigu.pdf
    • http://doveshanksbitters.com/uploads/1/3/0/5/130588318/f81c25.pdf
    • http://celestialcapitalpartners.com/uploads/1/3/0/6/130621082/6599330.pdf
    • http://condo440.com/uploads/1/3/0/7/130740166/21e0f78753544.pdf
    • http://stefanbrewer.com/uploads/1/3/0/2/130271124/lazezibusufa
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000aee5.bin
1ccaf8878ff46e12146b029398260fecd7815a8ce231ae890a9680e75a5a115e
pdf-font-stream PDF embedded font (sfnt) at offset 0xAEE5 10736 bytes