Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b45b0b6c0c9803d…

MALICIOUS

PDF

65.3 KB Authoring application: Karbon
MD5: b1f2d4576013d84a6f63d15ee91a3379 SHA-1: f7598367e036c3f4b11578594862dc184cb9ec65 SHA-256: 0b45b0b6c0c9803dae03f1e95ff54350a939d58027e91c4a3a4d011b125d16a9
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO spam or to redirect users to malicious content. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output strongly indicate malicious intent. The document body itself contains fragmented text related to 'Tecnologias emergentes 2018 informatica' and includes many of the same URLs found in the embedded URL list, reinforcing the link farm attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://parkandvinyl.com/uploads/1/3/0/5/130538922/5847219.pdf
    • http://kenna-kitchen.com/uploads/1/3/0/2/130271013/lodoliz_niwared_foziz_mirevefagewuwe.pdf
    • http://monkeesconcerts.com/uploads/1/3/0/6/130621335/guxuji.pdf
    • http://rightdevelopmentfoundation.com/uploads/1/3/0/2/130271068/f0bff2.pdf
    • http://lunux.marketingdigitalpolitico.com/uploads/2020/01/27/vokofamoserero_baxoditetalijus_dijol_nazaju.pdf
    • http://tiriku.mylatestfavoritething.com/uploads/2020/01/28/4a59f9c1ad.pdf
    • http://sealavienj.com/uploads/1/3/0/5/130538836/6676974.pdf
    • http://mysterycannabisclones.com/uploads/1/3/0/6/130620773/rifuzoxosokajulero.pdf
    • http://mylkshoppe.com/uploads/1/3/0/2/130270748/nujededijifi-xedeni.pdf
    • http://christinagdennehy.com/uploads/1/3/0/3/130324027/9039867.pdf
    • http://ruthmsmith.weebly.com/uploads/1/3/0/5/130543394/disiberota.pdf
    • http://buskbook.com/uploads/1/3/0/5/130589374/2077998.pdf
    • http://gepede.spinapro.ru/uploads/2020/01/28/wopot.pdf
    • http://lisocialsecuritylawyer.com/uploads/1/3/0/4/130488934/7466999.pdf
    • https://kuzibadufawut.weebly.com/uploads/1/3/0/2/130288630/murokewodesusogi.pdf
    • http://thegardenhead.com/uploads/1/3/0/5/130550716/70b55d5.pdf
    • http://rizopukof.en-help.center/uploads/2020/01/27/5784718.pdf
    • http://ccocciboutique.com/uploads/1/3/0/4/130477252/421041.pdf
    • http://nstarlight.com/uploads/1/3/0/4/130489175/2242595.pdf
    • http://naturalproducts.shop/uploads/1/3/0/3/130313193/nirikoxunifelov_gozulexedakob_xapisozogo.pdf
    • http://moms-life.net/uploads/1/3/0/5/130588678/3982418.pdf
    • http://meredithlubowphd.com/uploads/1/3/0/6/130604859/a418a65d.pdf
    • http://kylaconner.com/uploads/1/3/0/5/130540209/130540209.html#tecnologias+emergentes+2018+informatica
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017f6.bin
a76bb1b8c762054d96890f4d12c833cdfa0631727eadb0cf8a30669eb86959e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x17F6 10380 bytes
font_01_sfnt_off0000b8d1.bin
f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
pdf-font-stream PDF embedded font (sfnt) at offset 0xB8D1 16204 bytes