Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed71b907bc965e89…

MALICIOUS

PDF

55.0 KB Created: 2020-04-08 04:08:13 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 764d14cefbc47698f2e4725efb017c16 SHA-1: a7ae09cea4c0ca9d952a2a73372e1953c0d2a0f6 SHA-256: ed71b907bc965e89887b361c1abf4a36a3497883f399720e6259821e123e41a7
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links pointing to other PDFs hosted on various domains. This behavior is indicative of a link farm or a phishing campaign designed to distribute malicious content or redirect users to fraudulent sites. The document body itself appears to be garbled text related to PDF metadata and wkhtmltopdf, suggesting it's not intended for direct user consumption but rather as a container for the malicious links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lifecoach-international-online.com/uploads/1/3/0/7/130776385/130776385.html#c%C3%B4ng+th%E1%BB%A9c+t%C3%ADnh+%C4%91%E1%BA%A1o+h%C3%A0m+c%E1%BB%A7a+h%C3%A0m+s%E1%BB%91+m%C5%A9
    • http://acrescer.org/uploads/1/3/0/5/130589251/lekolozo.pdf
    • http://regeneraglobal.org/uploads/1/3/1/4/131453521/zamabijumoguno-xoralodalopune.pdf
    • http://spencerhamil.com/uploads/1/3/0/5/130550696/9883776.pdf
    • http://daniel-allan.com/uploads/1/3/0/5/130588672/1290013.pdf
    • http://nellytotssoftplay.com/uploads/1/3/0/6/130639085/905286fe79746.pdf
    • http://stephaniebright.net/uploads/1/3/0/8/130874244/karinabokinepik-sefurotup-vugiwifogeg.pdf
    • http://kreative-partners.com/uploads/1/3/0/5/130539341/ravigomibuw.pdf
    • http://acs-kw.com/uploads/1/3/1/3/131378840/11ebb0264a834.pdf
    • http://pintoananchorstore.com/uploads/1/3/0/8/130813536/ribenedelok.pdf
    • http://minnickmanagementhoa.com/uploads/1/3/1/3/131381921/nomew_metujuv.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000085e5.bin
4686dd6aea4996400fbb56e9993c617ee062960de894a42997fe91ba70437e4c
pdf-font-stream PDF embedded font (sfnt) at offset 0x85E5 11608 bytes
font_01_sfnt_off0000aa4d.bin
bfdb9807726f27db20985120cac427b7356445b2a6107f6ecfcb4bae6fb43a94
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA4D 25444 bytes