Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3232cf243b5b9a9…

MALICIOUS

PDF

24.8 KB Created: 2020-03-08 00:07:01 +02:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5c2bdc254a8427c9ea3548fc078c9574 SHA-1: 14d5f034c8c753e6e30dd4221ca6c07f07dc9fc7 SHA-256: b3232cf243b5b9a93505fd0dad23e55ea04f5914c123cb30f7284bc1bfbbf2bc
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious Link

The PDF file is identified as an image-only lure, typical of phishing campaigns. It contains numerous external links, suggesting a link farm or redirection mechanism. The primary URL, http://apmcivilengineering.com/uploads/1/3/0/3/130313500/130313500.html#cuadro+comparativo+de+adjetivos+posesivos+y+pronombres+personales, is likely the initial landing page for the attack. No scripts were extracted, but the structure strongly indicates a social engineering attack to redirect users to malicious content.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 24 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://apmcivilengineering.com/uploads/1/3/0/3/130313500/130313500.html#cuadro+comparativo+de+adjetivos+posesivos+y+pronombres+personales
    • http://darwinlazatinphotography.com/uploads/1/3/0/5/130539295/1520909.pdf
    • http://nycraftworks.com/uploads/1/3/0/5/130590180/266276ee513f1.pdf
    • http://baloyatees.com/uploads/1/3/0/3/130323555/bipiwos.pdf
    • http://tribelle.ca/uploads/1/3/0/6/130640214/2289664.pdf
    • http://paperstreetsalvage.com/uploads/1/3/0/6/130639506/8193542.pdf
    • http://upini.com/uploads/1/3/0/5/130551114/5895919.pdf
    • http://cuttingedgepoodles.com/uploads/1/3/0/4/130478210/pogaga.pdf
    • http://vmv66.com/uploads/1/3/0/7/130776079/eca735f0.pdf
    • http://hannysplace.com/uploads/1/3/0/7/130776411/fopaji_sigalugowotug_birenujet.pdf
    • http://ctownmarketing.com/uploads/1/3/0/7/130739631/jabeb.pdf
    • http://covines.com/uploads/1/3/0/2/130289313/9ce3a.pdf
    • http://scheduleashoot.com/uploads/1/3/0/2/130287527/6397859.pdf
    • http://servicepartnervanderveenassen.nl/uploads/1/3/0/2/130289503/xuwinaworije.pdf
    • http://mousepicked.com/uploads/1/3/0/4/130483739/e04dcd99.pdf
    • http://mta-sts.mx.tommypower.com/uploads/1/3/0/7/130739188/5304894.pdf