Malicious PDF — malware analysis report

Static analysis result for SHA-256 20e8fdf3c185f4eb…

MALICIOUS

PDF

49.6 KB Authoring application: PDFBox
MD5: bd8a27f49a91e4a0367e86ae4ae1b145 SHA-1: 6173bdc9a32e9226aeb0b566e7f4f2c6264e39ba SHA-256: 20e8fdf3c185f4eb64b05da7b5b56aa9279ee68a6372b19569ba493c3abc40aa
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to external PDF files. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URLs are likely used to redirect users to malicious content or for SEO poisoning. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://masstechlaw.net/uploads/1/3/0/4/130435553/garamikibazi_mowibexoxaw_nogewutugina_rufimorozoweg.pdf
    • http://thestorycollective.com/uploads/1/3/0/7/130739892/81793dc19.pdf
    • http://atlanta-hotel.co.uk/uploads/1/3/0/4/130476607/8029214.pdf
    • http://landscapedreaming.com/uploads/1/3/0/6/130605074/329890.pdf
    • http://barr-and-stroud.com/uploads/1/3/0/5/130588151/a3545b7200a369.pdf
    • http://footcentersofnorthcarolina.com/uploads/1/3/0/6/130640048/df7c43f99374f05.pdf
    • http://thefarmatcentralvillage.net/uploads/1/3/0/5/130547215/folozinibufebig_muzekatobados_xujareg.pdf
    • http://firstbookonline.net/uploads/1/3/0/2/130287371/c6b903.pdf
    • http://fartlyfe.com/uploads/1/3/0/5/130551046/fobipadelakutalav.pdf
    • http://southperthbaptist.org/uploads/1/3/0/5/130543653/6022711.pdf
    • http://55florida.com/uploads/1/3/0/4/130435811/fogeputagerojepuvuf.pdf
    • http://nanascountryporch.com/uploads/1/3/0/4/130489023/kinobujozugagum-juxevovideva.pdf
    • http://newmanstage.com/uploads/1/3/0/6/130604069/90cbc51e4b56ed5.pdf
    • http://gpufx.com/uploads/1/3/0/2/130273846/da7e333.pdf
    • http://lonlelyphotographer.online/uploads/1/3/0/5/130590392/bc4853bbfdb.pdf
    • http://midnightoilscompany.com/uploads/1/3/0/3/130323374/xoxufozusesevef.pdf
    • http://advance-it.net/uploads/1/3/0/6/130605374/130605374.html#compound+interest+calculator+monthly+saving
    • http://footcentersofnorthcarol

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005667.bin
583be4ccd96df79d156ab14a6c29c279ae907b6dbcec5883a979b7a55fb44212
pdf-font-stream PDF embedded font (sfnt) at offset 0x5667 1744 bytes
font_01_sfnt_off0000624d.bin
1fa49aa76670e7da182177f5e2388ce53c9be21b67657d9d3b12051db5922773
pdf-font-stream PDF embedded font (sfnt) at offset 0x624D 9372 bytes