Malicious PDF — malware analysis report

Static analysis result for SHA-256 143df12af5c7dfbd…

MALICIOUS

PDF

45.9 KB Authoring application: PDFBox
MD5: e3ee2cc6f3ee76415eed4b068a76fcc5 SHA-1: be6cc63599441c359d5f8c063df966196a3fb7bc SHA-256: 143df12af5c7dfbd8c5c2edb388ff91a7259121512ec4f57bb674d060c41340a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO spam or to distribute malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were extracted, the embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://northwalestreeservices.com/uploads/1/3/0/3/130313228/7722373.pdf
    • http://104450345337014885.com/uploads/1/3/0/2/130291040/zifit.pdf
    • http://anti-agingbyrjxjelly.com/uploads/1/3/0/3/130323602/xireraditasoxob.pdf
    • http://rivereasttravel.com/uploads/1/3/0/5/130540284/89e130a5caa2442.pdf
    • http://cprstars.org/uploads/1/3/0/6/130620142/6939058.pdf
    • http://uristlaboratory.ru/uploads/2020/01/29/gupifopowuxuvipisew.pdf
    • http://smithscateringholbrook.com/uploads/1/3/0/7/130775879/2344174.pdf
    • http://wastedtalentdesign.com/uploads/1/3/0/2/130271108/vekoru.pdf
    • http://carzonerepairandbody.com/uploads/1/3/0/4/130483242/wumiwo-fobololubazola-dinexunoduwibit.pdf
    • http://naramataplayschool.com/uploads/1/3/0/2/130270864/lifufazebofe-sakorefozudu-vizidijirefoj-wubuxagelifud.pdf
    • http://thecajunladies.com/uploads/1/3/0/6/130604161/rulowivaguxot_vajet_jitagedogadila_mebara.pdf
    • http://mscbmx.com/uploads/1/3/0/6/130639440/5116238.pdf
    • http://cyclebavaria.com/uploads/1/3/0/4/130476565/130476565.html#non+blanching+rash+guidelines
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001397.bin
75f2807fee5855146393a79b36cc63aba07a58a04b7cf60a28e2c34cd2594d7a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1397 8372 bytes
font_01_sfnt_off00006cd1.bin
cc2dc63fdacd8e30f2a9e94fc8117bdaad896be984ce33c37896a0392bf1eb25
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CD1 16096 bytes