Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a9fd00700778a0a…

MALICIOUS

PDF

42.8 KB Authoring application: Solid Converter PDF
MD5: 72291079dfbf23a2c38cedc3364d88a8 SHA-1: cb147a6c9474a2b4e0bc1ac0d124e48f02d3a269 SHA-256: 2a9fd00700778a0a0edc312f864046722d493ad7e48283d63e0c6e37f1db999d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The PDF contains a large number of embedded URLs pointing to other PDF files hosted on various domains. This technique is often used to create link farms for SEO manipulation or to distribute malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection intent. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://newtaiwankonus.com/uploads/1/3/0/4/130435601/juzak-kifozirorepop.pdf
    • http://shophairbytara.com/uploads/1/3/0/3/130323211/lutegekir-liraliv-jusoviwu.pdf
    • http://beardocustomcreations.com/uploads/1/3/0/7/130740323/jibiwejez.pdf
    • http://greenchicbeauty.com/uploads/1/3/0/3/130313108/danajovo.pdf
    • http://ryanjameslandscapingri.com/uploads/1/3/0/3/130379069/5383056.pdf
    • http://underthepinksun.com/uploads/1/3/0/8/130814863/vodawokerabe.pdf
    • http://roommatestheshow.com/uploads/1/3/0/4/130476816/7217663.pdf
    • http://clickpayservices.com/uploads/1/3/0/6/130639373/jejatu.pdf
    • http://shearwaterwarmbloods.ca/uploads/1/3/0/3/130323727/5436750.pdf
    • http://ourpleasureisland.com/uploads/1/3/0/9/130969772/4ff61aa.pdf
    • http://networkhairinc.com/uploads/1/3/0/2/130272932/mewekonuz-tujuluwe-puwuturufa.pdf
    • http://notaiobrunzo.it/uploads/1/3/0/4/130483911/61aec8f681.pdf
    • http://blackdiamondcontrols.com/uploads/1/3/0/4/130488069/7499356.pdf
    • http://bakerskidscrafts.com/uploads/1/3/0/5/130590531/3033909.pdf
    • http://lifecaredirections.com/uploads/1/3/0/5/130551226/momajupeniwiger.pdf
    • http://thesituationshortfilm.com/uploads/1/3/0/4/130488851/88663.pdf
    • http://mollypowers.com/uploads/1/3/0/5/130550782/8997442.pdf
    • http://medmalneverevent.net/uploads/1/3/0/7/130776063/lisevenabi-mobidogi-jakawodegozevi-rewazogoxus.pdf
    • http://elitehockeyleagues.com/uploads/1/3/0/5/130539225/mekin.pdf
    • http://www.maitri-midwifery.com/uploads/1/3/0/6/130604309/kexaje_mononisu.pdf
    • http://skulldiver.com/uploads/1/3/0/5/130540814/5006630.pdf
    • http://jeremyandkristina.com/uploads/1/3/0/3/130313224/rolomeduden.pdf
    • http://passport2pain.com/uploads/1/3/0/5/130589144/9864ab5a3.pdf
    • http://chantillybakery.net/uploads/1/3/0/8/130813786/5ca6459c.pdf
    • http://giancarlopalacios.com/uploads/1/3/0/3/130379142/1af841ab5d526b4.pdf
    • http://74-123-76-213.mgwnet.com/uploads/1/3/0/7/130738700/130738700.html#rbse+class+10th+sample+paper+2019
    • http://www.maitri-midwifery.com/uploads/1/3/0/6/13060430

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002dc7.bin
887fbafc80eeb8acf70478a467f3fa601fa9cee5df9da5f6f2bafee9c2f85be5
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DC7 7220 bytes
font_01_sfnt_off000042fa.bin
ee912533a93869167d7269a9f92c3697e51fa8f28f1b15e82cbbef7097d21d2d
pdf-font-stream PDF embedded font (sfnt) at offset 0x42FA 7772 bytes