Malicious PDF — malware analysis report

Static analysis result for SHA-256 23ba3229df703cad…

MALICIOUS

PDF

35.5 KB Authoring application: Pdftk First seen: 2021-01-11
MD5: dbd2b4b3f9728d724be07c0c4e546bd9 SHA-1: b4cfb61260b21cfe227574e7e370069dd4f1f8ad SHA-256: 23ba3229df703cad2d8cc8e4500a50a93f9720d55d846b722de6e201157c5568
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vipiski-besplatno28.icu/uploads/2020/01/28/2100012.pdf In PDF document text
    • http://prettiekitteedeals.com/uploads/1/3/0/6/130603861/pilodopula.pdfIn PDF document text
    • http://smartx24.ru/uploads/2020/01/28/10ad22d8.pdfIn PDF document text
    • http://ellijacobs.com/uploads/1/3/0/6/130605125/6766596.pdfIn PDF document text
    • https://sijawevape.weebly.com/uploads/1/3/0/4/130488152/6a8dae.pdfIn PDF document text
    • http://jekonudit.comparateurdesbanques.com/uploads/2020/01/27/75e5adc8deb.pdfIn PDF document text
    • http://nebenivoj.globaltoursjourneys.com/uploads/2020/01/28/sopawefixu-jiduloxupuwaba-gujetinexenape-koxawuzasu.pdfIn PDF document text
    • http://danielreist.org/uploads/1/3/0/5/130543575/130543575.html#google+chrome+ubuntu+commandIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11AD 8552 bytes
SHA-256: 7efe1e3eafe57cd5a9e08c0f1fd2b5ef84b6712c9aa4717235ec1d11dcc26492