Malicious PDF — malware analysis report

Static analysis result for SHA-256 0fa9c6dc55931d3b…

MALICIOUS

PDF

37.1 KB Authoring application: Pdftk
MD5: 159ab90bbb31e032d3a2e46185c26d3d SHA-1: 07e37e44153e685a04b6869d1759e345d5be287d SHA-256: 0fa9c6dc55931d3b9970b143bddec4c7a9a6ce51f4b37107e033aa05ce5984eb
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains a large number of embedded links, identified by the 'PDF_SEO_LINK_FARM' heuristic. The document body text, though heavily corrupted, contains fragments of financial language suggesting an invoice or payment lure. The embedded links likely lead to malicious sites for phishing or malware distribution. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.lowellpowerequipment.com/uploads/1/3/0/5/130588659/sidovorewak.pdf
    • http://alexistrucking.com/uploads/1/3/0/5/130551746/wakaxu_vufojij.pdf
    • http://foodlabelmaven.org/uploads/1/3/0/2/130288775/fotoduv_wuleji_zimajaruwef_tetujavus.pdf
    • http://qqblog.net/uploads/1/3/0/3/130313215/1fafc21e25b4db.pdf
    • http://nancyzhang0313.com/uploads/1/3/0/3/130323789/jokevulozemexop.pdf
    • http://tonebabyrecords.com/uploads/1/3/0/6/130604601/6009395.pdf
    • http://bballguru.com/uploads/1/3/0/6/130639042/e5534db0a.pdf
    • http://statesvstaxscam.com/uploads/1/3/0/3/130313114/267b2f0.pdf
    • http://tcgplanet.com/uploads/1/3/0/6/130603865/6e2da.pdf
    • http://ontherolljoplin.com/uploads/1/3/0/5/130543050/bifebe_zedonivakemi_febak_xovutakililegok.pdf
    • http://priyagandhi.net/uploads/1/3/0/4/130476481/ligetugelugepituvel.pdf
    • http://wattplants.com/uploads/1/3/0/2/130289502/mabiwufilubadufuf.pdf
    • http://mylocalpayroll.com/uploads/1/3/0/3/130324248/c7432d.pdf
    • http://hostmaster.loveinmylife.co.uk/uploads/1/3/0/5/130544446/f9bedf810e1f1.pdf
    • http://mindfulmoto.us/uploads/1/3/0/7/130776142/kotujamukoloresawa.pdf
    • http://wellfleetpirate.com/uploads/1/3/0/4/130483294/dozodosad.pdf
    • http://webdisk.cuisinierssansfrontieres.org/uploads/1/3/0/5/130550684/pubazanaxuwog.pdf
    • http://tooldesignsolutions.com/uploads/1/3/0/4/130476417/4695409.pdf
    • http://mx.pugetsounddoulas.com/uploads/1/3/0/2/130270994/8072682.pdf
    • http://mid-atlanticofficeportfolio.com/uploads/1/3/0/7/130776174/kiken-tomapoxiwufabi.pdf
    • http://agentflamingo.com/uploads/1/3/0/4/130476502/devonaf.pdf
    • http://suburbansubterranean.com/uploads/1/3/0/7/130776025/tofulavitofuv_womifo_kafulilomubuxa_nabijibefur.pdf
    • http://eceportfoliosrh.com/uploads/1/3/0/5/130544754/2501561.pdf
    • http://nwrilg.net/uploads/1/3/0/7/130739483/9924047.pdf
    • http://mitrarheumatology.com/uploads/1/3/0/6/130621776/gekefiz_tiseba_bowiwamo.pdf
    • http://74-123-79-113.mgwnet.com/uploads/1/3/0/5/130540359/130540359.html#what+does+accounting+method+cash+or+accrual+mean

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002e4e.bin
3343d6c283561a11aad4d7857f201a65bc783a74f4ef01d4ad6ccf8d887ec3d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x2E4E 7140 bytes