Malicious PDF — malware analysis report

Static analysis result for SHA-256 019c9860a5dc3d40…

MALICIOUS

PDF

39.6 KB Authoring application: Pdftk
MD5: ed41b20b065e780bfb427dac9e31688c SHA-1: 3c322cce92308ea19447d150e8720099ac0695db SHA-256: 019c9860a5dc3d40c5f9cd11edc324b60147b502923dd5bc7b4bcc897a44af16
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link-farming or redirection scheme. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. The embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sydneyft.com/uploads/1/3/0/4/130476699/720c7540dd812.pdf
    • http://shoebrewnation.com/uploads/1/3/0/3/130323328/4575748.pdf
    • http://ratasenadopcion.weebly.com/uploads/1/3/0/4/130490665/4331970.pdf
    • http://rhonddaladieshockey.co.uk/uploads/1/3/0/7/130738715/1390565.pdf
    • http://gt-autos.com/uploads/1/3/0/6/130604420/bower_favurafukapo_vugijarevobef_posugewotukosur.pdf
    • http://mi6app.com/uploads/1/3/0/6/130604196/teradimumuwa.pdf
    • http://ncsocietyofengineers.com/uploads/1/3/0/2/130270900/64ae4.pdf
    • http://netmagnetism.ca/uploads/1/3/0/3/130313612/kufujugeda-zadize-sofiwar.pdf
    • http://teamwrightbrothers.com/uploads/1/3/0/6/130639331/jedoxilag-wofofanu-zevivivulis-gefitu.pdf
    • http://thediazobserver.com/uploads/1/3/0/4/130477492/zitiniwazuwo_kamarez.pdf
    • http://ricefamilyfarms.com/uploads/1/3/0/5/130588783/138a0fc3562.pdf
    • http://miami.momotombochocolatefactory.com/uploads/1/3/0/4/130483349/130483349.html#annual+report+2019+australia

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012d9.bin
8bf198d69ca1168ec9c12fd7d9f54926c6859901bf608242be57285be3462636
pdf-font-stream PDF embedded font (sfnt) at offset 0x12D9 7864 bytes