Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f95a401cd00a5c5…

MALICIOUS

PDF

85.7 KB Authoring application: SWFTools First seen: 2021-01-11
MD5: e124f2cd616a419491ea97089ebccf3a SHA-1: da11cf017d49efecd272bcd77897e19691b0395f SHA-256: 1f95a401cd00a5c5e7af5bb44e8eb178c4e84c5e1969e26c7c079c719d7d3ac1
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jurinaphotography.com/uploads/1/3/0/4/130488851/retenujeto.pdf In PDF document text
    • http://fol.oldi-nix-dns.info/uploads/2020/01/27/7825878.pdfIn PDF document text
    • http://xajo.botanicart.ru/uploads/2020/01/28/repokizasupule.pdfIn PDF document text
    • http://xuronig.copyrightcontact-10000642147218.com/uploads/2020/01/28/a2ddd.pdfIn PDF document text
    • http://putibikope.kardio-control.ru/uploads/2020/01/28/785526.pdfIn PDF document text
    • http://zabota.chess-nut.com/uploads/2020/01/28/4495849.pdfIn PDF document text
    • http://towijefak.domcrawford.online/uploads/2020/01/28/luweje-nojosujuti-fataw.pdfIn PDF document text
    • http://hamptonsbailbonds.com/uploads/1/3/0/5/130545382/9487254.pdfIn PDF document text
    • http://xasula.audiostart42.icu/uploads/2020/01/28/02e5a95ed32df.pdfIn PDF document text
    • https://sevupunumikage.weebly.com/uploads/1/3/0/5/130588906/8934254.pdfIn PDF document text
    • http://werenuboj.rus-snow.ru/uploads/2020/01/29/jigomisoxurenu_keraputusof_jawulunipapubek_lizefetesik.pdfIn PDF document text
    • http://wotupatur.pinhs-ap.com/uploads/2020/01/28/17a40c75045cc.pdfIn PDF document text
    • http://dora.menurotrin.ru/uploads/2020/01/29/wimexaselotevi_xedosawigebazev_zogudovixawabe_dalivujoxu.pdfIn PDF document text
    • http://unsocialmediapp.com/uploads/1/3/0/6/130620865/49e550e8184.pdfIn PDF document text
    • http://zilekixu.konstantinostapenko.com/uploads/2020/01/27/mebabukada.pdfIn PDF document text
    • https://fufenoxaza.weebly.com/uploads/1/3/0/2/130272928/bodez_lilobeduw_sawupedi.pdfIn PDF document text
    • http://iwit-ism.com/uploads/1/3/0/5/130542971/7280881.pdfIn PDF document text
    • http://banglanews.pro/uploads/2020/01/27/aba7f.pdfIn PDF document text
    • http://xaw.antiviruseprotectiononline.xyz/uploads/2020/01/28/6316342.pdfIn PDF document text
    • http://whiteteethteen.com/uploads/1/3/0/4/130483617/130483617.html#bojhena+shey+bojhena+watch+online+frIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://www.adobe.com/).NotoIn PDF document text
    • http://www.google.com/get/noto/http://www.adobe.com/type/ThisIn PDF document text
    • http://scripts.sil.org/OFLNotoIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000018ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18AD 13796 bytes
SHA-256: b37bf2e01b4a228ada57ebebaf0c4d2b06ac3316a2cbf0a638092ad57018bf7f
font_01_sfnt_off00006562.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6562 16068 bytes
SHA-256: 6db2f878e0fd57d3a351d0d81a5ccd7b58f68df6728dadc3aee3ebeb1a1d6e60
font_02_sfnt_off000103bd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x103BD 5760 bytes
SHA-256: 3c704b1071b658e41a345615b8549be9d51c1d0c037fde16b5fae5a50639a579
font_03_sfnt_off00011596.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11596 2732 bytes
SHA-256: 50224c6c483bfa86a10f62efd7baa2c756f8036c0a911ebd537387e21b2fb6f3