Malicious PDF — malware analysis report

Static analysis result for SHA-256 afa5f0c641d2dd5b…

MALICIOUS

PDF

45.5 KB Created: 2020-03-20 03:41:27 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 87d89daa94ea90c54f37d70d9695c4fe SHA-1: ee6183974d126e773f4b3ad08c0e5946e826e44f SHA-256: afa5f0c641d2dd5b32f1d2cdf21631fc82bc4b989cbd5705f750b6ce0646191d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of external links, many of which are hosted on unrelated domains and appear to be part of a link farm. The document body text, though partially corrupted, suggests a lure related to GPS software updates. The primary attack pattern involves directing users to these numerous external URLs, likely for further exploitation or phishing. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://neighbornotary.com/uploads/1/3/0/2/130289096/130289096.html#atualiza%C3%A7%C3%A3o+gps+garmin+nuvi+42lm
    • http://realestate.quickqualityphotos.com/uploads/1/3/0/7/130775055/113512.pdf
    • http://www.tonydaltondds.com/uploads/1/3/0/6/130621190/konatodunojelovof.pdf
    • http://duganspecialties.com/uploads/1/3/0/2/130288391/kevor.pdf
    • http://mail.lewisandclarkriverboat.com/uploads/1/3/0/3/130324386/8519679.pdf
    • http://implicit7.net/uploads/1/3/1/1/131164568/redujuso-wapumu-guvezexa-magemad.pdf
    • http://enactum.net/uploads/1/3/0/5/130550986/mesugaw-fadolirakurusa.pdf
    • http://looe-festival-of-the-sea.com/uploads/1/3/0/7/130739437/8557949.pdf
    • http://asianairspace.com/uploads/1/3/0/6/130621998/5517975.pdf
    • http://ethnictails.com/uploads/1/3/0/6/130620991/6159628.pdf
    • http://selectiveserviceregistration.com/uploads/1/3/0/8/130874495/xumodozu_lutow_wisufidimu_pabizubajuwudif.pdf
    • http://kellmercerlaw.com/uploads/1/3/1/0/131071151/b7c2afe9f61c49d.pdf
    • http://dadgumoutdoors.com/uploads/1/3/0/5/130590257/pefoxoje-goronakaxofef-widugapab-xiton.pdf
    • http://nvintl.com/uploads/1/3/0/6/130604497/detavudu_xagowoxo_janesanupitas_fezolejit.pdf
    • http://coachingsportifpremium.net/uploads/1/3/0/7/130776351/xijumaxaweke-wenugemaxovuven-vepow.pdf
    • http://mycreativebeing.com/uploads/1/3/0/8/130813366/boduv.pdf
    • http://cassandrayoungphotography.com/uploads/1/3/0/2/130291579/7162220.pdf
    • http://eagleeyeaerials.net/uploads/1/3/0/6/130621683/edd34218426b46.pdf
    • http://www.tannlegereiser.no/uploads/1/3/0/6/130639443/loxokoful_rezejikud_lexopef.pdf
    • http://gorgeresilience.org/uploads/1/3/0/2/130287521/4262022.pdf
    • http://fairtradelarimar.org/uploads/1/3/0/6/130639068/sadolaxijav.pdf
    • http://www.bridgingthepathtoparadise.com/uploads/1/3/0/6/130620687/vukukil_zamofepe.pdf
    • http://dothedavey.com/uploads/1/3/0/4/130436071/7329913.pdf
    • http://reopt.net/uploads/1/3/0/4/130483270/483004.pdf
    • http://kewsocial.com/uploads/1/3/0/6/130603913/4d3ba8c0.pdf
    • http://quirkybev.com/uploads/1/3/0/7/130738989/3406448.pdf
    • http://dothedavey.com/uploads/1/3/0/4/130436071/7329913.pd
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007d94.bin
c8962bf1339ea11fb48b2c71eb7547bc2f4d972ead3bc21ee86c4c96a725a08a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D94 8992 bytes
font_01_sfnt_off00009f75.bin
a2f0e64d6975656d959a0794b9a965349b6a87240c16eb122ddb64596f86590d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F75 1704 bytes