Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c611636da61fee7…

MALICIOUS

PDF

69.0 KB Authoring application: SWFTools
MD5: b6bd1a36a799a6d22be7ddcc3e19fe8f SHA-1: bbe0291f4bc3222e201658bfc2696d775b93591c SHA-256: 3c611636da61fee78240807da50fc29b4a863c8cb8b4f7d19a7cb6e040f28211
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' directly identifies this behavior. Additionally, the 'SE_LOLBIN_RUN_COMMAND' heuristic suggests that the document may contain instructions for executing commands, potentially leveraging tools like PowerShell or mshta to download and execute further payloads from the linked URLs. The ClamAV detection further confirms its malicious nature.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://palomarpools.com/uploads/1/3/0/5/130543855/5971741.pdf
    • http://mta-sts.mx.nwiioa.org/uploads/1/3/0/3/130313177/5371726.pdf
    • http://postboxsucks.net/uploads/1/3/0/3/130323407/7626d2c39dcb9e8.pdf
    • http://www.forevercise.com/uploads/1/3/0/7/130740056/vufibibodasepifokinu.pdf
    • http://bealegacybuilder.com/uploads/1/3/0/6/130639580/7542098.pdf
    • http://betaqua.com/uploads/1/3/0/6/130639855/barajofoluxosi-noxabetubokem-taxobe-puboxaxiwavum.pdf
    • http://leanqueue.com/uploads/1/3/0/7/130740082/wujafesela.pdf
    • http://imaginaryrats.com/uploads/1/3/0/4/130476917/d77b16.pdf
    • http://royaltrainridesrentals.com/uploads/1/3/0/2/130288379/jatatumegewewif-muvusovalot-bivem-lafadoboxapa.pdf
    • http://spccmd.com/uploads/1/3/0/3/130313169/daraxa.pdf
    • http://myrole.tech/uploads/1/3/0/7/130776176/dixipove-bofixatejut-nodigadona-tepawukagukob.pdf
    • http://purephoenix.tv/uploads/1/3/0/6/130620370/a9d41.pdf
    • http://friendsofmuirvalley.org/uploads/1/3/0/7/130775135/loderasoxok.pdf
    • http://jamesjersin.com/uploads/1/3/0/5/130589449/e9a87f40453f9b.pdf
    • http://my-mindful-mind.com/uploads/1/3/0/7/130775268/dejoputanos.pdf
    • http://magicalcryptofriends.net/uploads/1/3/0/5/130588286/3476591.pdf
    • http://notonmeth.com/uploads/1/3/0/4/130483765/munedobotunow-zixitovimaxa.pdf
    • http://asociacionpro-indefensos.org/uploads/1/3/0/6/130639027/0cfed1d4d33.pdf
    • http://modestomasonry.com/uploads/1/3/0/5/130539497/4916975.pdf
    • http://www.amglasswork.com/uploads/1/3/0/2/130288563/3373904.pdf
    • http://rhettasreliablelips.com/uploads/1/3/0/7/130775520/3048cdd.pdf
    • http://74-123-73-116.mgwnet.com/uploads/1/3/0/9/130969774/130969774.html#tecnica+de+lichtenstein+para+hernia+inguinal+pdf

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001500.bin
180f04e4bb2e9cf6c844f18788aa20322c26c790b0e02b8a7ab20e5536374f1c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1500 11904 bytes
font_01_sfnt_off0000b89c.bin
e91619dfd4c72a85464d95ef1ba4e67df13020651c42071bafbe521a61d9f7fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xB89C 2652 bytes
font_02_sfnt_off0000c168.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0xC168 16036 bytes