Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c611636da61fee7…

MALICIOUS

PDF

69.0 KB Authoring application: SWFTools First seen: 2020-09-07
MD5: b6bd1a36a799a6d22be7ddcc3e19fe8f SHA-1: bbe0291f4bc3222e201658bfc2696d775b93591c SHA-256: 3c611636da61fee78240807da50fc29b4a863c8cb8b4f7d19a7cb6e040f28211
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' directly identifies this behavior. Additionally, the 'SE_LOLBIN_RUN_COMMAND' heuristic suggests that the document may contain instructions for executing commands, potentially leveraging tools like PowerShell or mshta to download and execute further payloads from the linked URLs. The ClamAV detection further confirms its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://palomarpools.com/uploads/1/3/0/5/130543855/5971741.pdf In PDF document text
    • http://mta-sts.mx.nwiioa.org/uploads/1/3/0/3/130313177/5371726.pdfIn PDF document text
    • http://postboxsucks.net/uploads/1/3/0/3/130323407/7626d2c39dcb9e8.pdfIn PDF document text
    • http://www.forevercise.com/uploads/1/3/0/7/130740056/vufibibodasepifokinu.pdfIn PDF document text
    • http://bealegacybuilder.com/uploads/1/3/0/6/130639580/7542098.pdfIn PDF document text
    • http://betaqua.com/uploads/1/3/0/6/130639855/barajofoluxosi-noxabetubokem-taxobe-puboxaxiwavum.pdfIn PDF document text
    • http://leanqueue.com/uploads/1/3/0/7/130740082/wujafesela.pdfIn PDF document text
    • http://imaginaryrats.com/uploads/1/3/0/4/130476917/d77b16.pdfIn PDF document text
    • http://royaltrainridesrentals.com/uploads/1/3/0/2/130288379/jatatumegewewif-muvusovalot-bivem-lafadoboxapa.pdfIn PDF document text
    • http://spccmd.com/uploads/1/3/0/3/130313169/daraxa.pdfIn PDF document text
    • http://myrole.tech/uploads/1/3/0/7/130776176/dixipove-bofixatejut-nodigadona-tepawukagukob.pdfIn PDF document text
    • http://purephoenix.tv/uploads/1/3/0/6/130620370/a9d41.pdfIn macro / runtime command snippet
    • http://friendsofmuirvalley.org/uploads/1/3/0/7/130775135/loderasoxok.pdfIn PDF document text
    • http://jamesjersin.com/uploads/1/3/0/5/130589449/e9a87f40453f9b.pdfIn PDF document text
    • http://my-mindful-mind.com/uploads/1/3/0/7/130775268/dejoputanos.pdfIn PDF document text
    • http://magicalcryptofriends.net/uploads/1/3/0/5/130588286/3476591.pdfIn PDF document text
    • http://notonmeth.com/uploads/1/3/0/4/130483765/munedobotunow-zixitovimaxa.pdfIn PDF document text
    • http://asociacionpro-indefensos.org/uploads/1/3/0/6/130639027/0cfed1d4d33.pdfIn PDF document text
    • http://modestomasonry.com/uploads/1/3/0/5/130539497/4916975.pdfIn PDF document text
    • http://www.amglasswork.com/uploads/1/3/0/2/130288563/3373904.pdfIn PDF document text
    • http://rhettasreliablelips.com/uploads/1/3/0/7/130775520/3048cdd.pdfIn PDF document text
    • http://74-123-73-116.mgwnet.com/uploads/1/3/0/9/130969774/130969774.html#tecnica+de+lichtenstein+para+hernia+inguinal+pdfIn PDF document text
    • http://myrole.tIn macro / runtime command snippet
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001500.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1500 11904 bytes
SHA-256: 180f04e4bb2e9cf6c844f18788aa20322c26c790b0e02b8a7ab20e5536374f1c
font_01_sfnt_off0000b89c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB89C 2652 bytes
SHA-256: e91619dfd4c72a85464d95ef1ba4e67df13020651c42071bafbe521a61d9f7fc
font_02_sfnt_off0000c168.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC168 16036 bytes
SHA-256: 779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63