Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6ae600df51aa100…

MALICIOUS

PDF

37.8 KB Created: 2020-03-30 03:40:20 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 6c6a56d9f106f17301ba41da4547a3eb SHA-1: 62d54bff2beafa95e5b937a707c7651bef6934fb SHA-256: d6ae600df51aa100594684d1737059a686cffda07f7ea481d819e7b0f69fe98f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a link farm or SEO poisoning tactic. The document body contains garbled text but includes a reference to 'Los cuatro pilares de la educación inicial', which appears in one of the extracted URLs. No scripts were extracted from this sample. The primary attack pattern involves directing users to a multitude of external PDF resources.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://amazingjourneytravel.voyagerwebsites.com/uploads/1/3/0/7/130775570/130775570.html#los+cuatro+pilares+de+la+educaci%C3%B3n+inicial
    • http://hannahpipkinreading.com/uploads/1/3/1/1/131163744/9957279.pdf
    • http://cleverumzug.net/uploads/1/3/0/5/130551072/1424009.pdf
    • http://milesstern.com/uploads/1/3/0/7/130776110/nadiposuxatiponajos.pdf
    • http://vacationrentalsny.com/uploads/1/3/0/6/130620712/189733.pdf
    • http://govfilingsonline.biz/uploads/1/3/0/3/130379183/4975025.pdf
    • http://mobilenotarywithbobbi.com/uploads/1/3/0/4/130436299/noroze.pdf
    • http://evpcs.com/uploads/1/3/0/4/130476873/xidipoxoxodemome.pdf
    • http://katalystvirtual.com/uploads/1/3/0/5/130589354/22a4f572a2426ba.pdf
    • http://castlesandcouture.com/uploads/1/3/1/1/131163683/jixuvototixor.pdf
    • http://allyourteeth.com/uploads/1/3/0/5/130539734/3200eea2abbb1.pdf
    • http://treasurevalleygourmetsalts.com/uploads/1/3/0/8/130814397/7016346.pdf
    • http://sewmanyblessings.org/uploads/1/3/0/5/130543133/fekowiwupimokex.pdf
    • http://do-what-works.net/uploads/1/3/0/4/130476347/4881484.pdf
    • http://myearlylearningbox.com/uploads/1/3/0/5/130545278/a9f32a2.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069c7.bin
d7af953b4bfdf833d02e86a91063a0b78496be8bf7396d505a5af1a976a63c87
pdf-font-stream PDF embedded font (sfnt) at offset 0x69C7 8288 bytes