Malicious PDF — malware analysis report

Static analysis result for SHA-256 330818e178660718…

MALICIOUS

PDF

42.5 KB Authoring application: LibreOffice First seen: 2021-01-23
MD5: 3daef7ae0d9a9eae2664476ec43c9222 SHA-1: 318fabd1577be9b9cc5b1d2a20a9b158e7cbbd3a SHA-256: 330818e1786607183c7909aaa8964d08de8fa9aef71d41ab86d2d5d5bd30411f
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://feb.chekhov-tour.ru/uploads/2020/01/29/lisamowenorup.pdf In PDF document text
    • https://gajidekuw.weebly.com/uploads/1/3/0/5/130588885/6098997.pdfIn PDF document text
    • http://carlyhaecktherapy.weebly.com/uploads/1/3/0/4/130483153/xowilikuxotet_vokebonesolab_naxatokap.pdfIn PDF document text
    • http://555-jeudirouge.fr/uploads/1/3/0/5/130590716/a99db238.pdfIn PDF document text
    • http://cincoranchpoolbuilders.com/uploads/1/3/0/6/130620651/motiwa-mizofevokosemiz-guwolex.pdfIn PDF document text
    • http://james-read.com/uploads/2020/01/28/af951aa3d78ef.pdfIn PDF document text
    • http://voridul.colt-russia.ru/uploads/2020/01/29/9609030.pdfIn PDF document text
    • http://zodiac-whisperer.com/uploads/1/3/0/3/130379049/kozukogekidupin.pdfIn PDF document text
    • http://jum.support-account.net/uploads/2020/01/27/kimeresagazalezino.pdfIn PDF document text
    • http://defense-elec-corp.com/uploads/1/3/0/5/130590209/130590209.html#diferencia+entre+autista+y+aspergerIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001466.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1466 9160 bytes
SHA-256: 8f7c938ce69e744d7831a3adb2bec7ade7f7b906e7bacbf4f16e656e313e92db