Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0412a7df82a2d44…

MALICIOUS

PDF

55.3 KB Created: 2020-04-23 02:40:12 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 4179e11a91ca82ff988358f961572d88 SHA-1: 0413afce4f5c981cb8b5f0d781d161dcc5fed033 SHA-256: c0412a7df82a2d445bf33ccf7889d70abb9415fbe263f022ebd1be54f5ee4fec
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or a distribution mechanism for further malicious content. The document body is heavily obfuscated and contains what appears to be metadata from the wkhtmltopdf tool, but no direct malicious script or payload was extracted. The primary attack vector appears to be directing users to these external resources.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tgigaming.com/uploads/1/3/0/6/130604495/130604495.html#basic+pronunciation+exercises+pdf
    • http://reteprofesionisti.com/uploads/1/3/0/4/130488920/8cdd9636bfe32.pdf
    • http://writingcentered.org/uploads/1/3/0/8/130874670/248651.pdf
    • http://fantasyhomesolutionsusa.com/uploads/1/3/0/6/130604098/nizitovuxepugigi.pdf
    • http://mermaidcaye.com/uploads/1/3/0/6/130640162/7499030.pdf
    • http://meliorsquashcourtmaintenance.com/uploads/1/3/0/3/130313488/ce98343a.pdf
    • http://karimlemec.it/uploads/1/3/0/2/130272484/vokezo.pdf
    • http://bigcoffeecup.com/uploads/1/3/0/5/130589391/f1b8b97e4.pdf
    • http://suzitakahashi.com/uploads/1/3/0/5/130550926/motidude_wuzugukosibud_xusozepa_tisuba.pdf
    • http://bjallar-handverk.com/uploads/1/3/0/6/130621900/vonuxida.pdf
    • http://mrsgingercunningham.com/uploads/1/3/0/4/130483963/razizo-retoxuka.pdf
    • http://ltc360.com/uploads/1/3/0/7/130739103/sudefufesesanut.pdf
    • http://securityprojects.be/uploads/1/3/0/8/130814805/pawodipenuwivom.pdf
    • http://shopatwestparksc.com/uploads/1/3/0/5/130544635/fatafidadawuw-zubafudovex-lakavot-venevo.pdf
    • http://malko-et-compagnie.com/uploads/1/3/1/4/131455508/lagokevujajekevadum.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000793e.bin
7d442c8d8fbd63b3502b7d223a8c0c9ff7232061c8d960313effed9b2e42ee8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x793E 9504 bytes
font_01_sfnt_off00009c6a.bin
16ff61d3ffb6180cfa0644cf78565bc3d301cd6f94cd0bfd904666d5ddffaca4
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C6A 4532 bytes
font_02_sfnt_off0000ab0f.bin
11eff0542ee112a7a4f3d5fa86892f13f7f7c80edb17354215cea33bb7714487
pdf-font-stream PDF embedded font (sfnt) at offset 0xAB0F 2768 bytes
font_03_sfnt_off0000b4d9.bin
04d57584e386381e1ea5f02cbfc9b227f50097366dd03d9e4549a4e2ad7126e9
pdf-font-stream PDF embedded font (sfnt) at offset 0xB4D9 17108 bytes