Malicious PDF — malware analysis report

Static analysis result for SHA-256 11d7962f9eab26ca…

MALICIOUS

PDF

53.6 KB Authoring application: PDFBox
MD5: a61362e0260508a0384711241d9dbe64 SHA-1: d0549603a0949748327ec3ba22c6f2e124581247 SHA-256: 11d7962f9eab26caebdf754e4e36120ad489990d27b26bf8133eb2c7c1632e7d
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of embedded links to external PDF files, identified as a link farm. This is a common technique used in phishing campaigns to direct users to malicious content. The ClamAV detection and ML classifier further support its malicious nature, indicating it is likely a phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weri.mimosaweb.com/uploads/2020/01/28/2656558.pdf
    • http://oyegeneralmotors.com/uploads/1/3/0/2/130274151/ac302b544076.pdf
    • http://mitchellwenkus.com/uploads/1/3/0/4/130489175/f2e622b2be4.pdf
    • http://djdbaker.com/uploads/1/3/0/6/130620835/f40275592b64.pdf
    • http://shhugarshop.com/uploads/1/3/0/4/130483868/razix.pdf
    • http://agentlemansartwork.com/uploads/1/3/0/5/130590310/a418bdc208bf6.pdf
    • http://pisgahprovisions.com/uploads/1/3/0/6/130605080/716cde.pdf
    • http://spanglishprints.com/uploads/1/3/0/6/130604590/jajowakodesineb.pdf
    • https://memusomiwapab.weebly.com/uploads/1/3/0/5/130543059/getolubojepaf.pdf
    • http://saraandrewswriting.com/uploads/1/3/0/2/130288453/2293784.pdf
    • http://mylittletruffles.com/uploads/1/3/0/3/130313359/bajiripajara.pdf
    • http://ayasuda.com/uploads/1/3/0/6/130621882/130621882.html#heart+failure+guideline+thai+2018
    • http://linux.thai.net/projects/fonts-tlwg
    • http://www.thaitux.info

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000142b.bin
b7129efb1760bb40a0238de7fa4ba024a4ab673f25679050ad2db9abb9fc622c
pdf-font-stream PDF embedded font (sfnt) at offset 0x142B 8320 bytes
font_01_sfnt_off0000727c.bin
a90bfa600e0cff00043f396da088926a2fc53804b5075f038eb2f97f4be4c17c
pdf-font-stream PDF embedded font (sfnt) at offset 0x727C 20872 bytes