Malicious PDF — malware analysis report

Static analysis result for SHA-256 116e99f31ba02dcb…

MALICIOUS

PDF

41.9 KB Authoring application: LibreOffice
MD5: 0c200a8425cc64ffc68e5d63b0db83e7 SHA-1: bf0c2088970a7ebf44a5431b51ec1bcfdf7e67c5 SHA-256: 116e99f31ba02dcb2ad38d7934cf75f6f55f4124beba65e4c2424c0533ed0e0a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO poisoning or to distribute malware. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs are the primary IOCs, suggesting a campaign to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://120lakeshoredrive.com/uploads/1/3/0/6/130621124/xebar_xemopamigus_kikanupis_piruguwutos.pdf
    • http://mirkamalmi.com/uploads/1/3/0/6/130621095/7953814.pdf
    • http://australiancouncilofhinduclergy.org/uploads/1/3/0/6/130639646/4660618.pdf
    • http://zamubedez.tmass.online/uploads/2020/01/28/rolonupagu.pdf
    • http://quantumspirit.us/uploads/1/3/0/5/130543054/2549b9e472f.pdf
    • http://trustedadvocates.org/uploads/1/3/0/6/130621462/568e177bcb.pdf
    • http://cefcamas.org/uploads/1/3/0/7/130738633/lixukazenala.pdf
    • http://tos.tt12bb.top/uploads/2020/01/28/6082790.pdf
    • http://smithsolarlab.com/uploads/1/3/0/3/130323631/nunixinuvozisaz.pdf
    • http://tenzafansite.com/uploads/1/3/0/6/130639750/09a411.pdf
    • http://santaclaritascreenprinting.com/uploads/1/3/0/6/130639848/zipenawirusadow.pdf
    • http://allisonjjanda.com/uploads/1/3/0/4/130483728/rutuluxubozujepoxap.pdf
    • http://5pointauto.com/uploads/1/3/0/5/130588880/130588880.html#bhoot+bangla+full+hd+movie
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001491.bin
b06430bbdfe5532eea90aa613ce452099616efbae53db50683df1cbd9c17c098
pdf-font-stream PDF embedded font (sfnt) at offset 0x1491 8032 bytes
font_01_sfnt_off00005f4e.bin
56f84f2950559fd80ab1937f656631db6d9e66949774c777572e241db7d8f31d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F4E 7180 bytes