Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c8628c2b712c91f…

MALICIOUS

PDF

36.8 KB Authoring application: OpenOffice Draw
MD5: ca5190fc93c52eb235067f60260ba8ec SHA-1: f2961714ab27c87aefaf7d36aeda2e2018ce59ae SHA-256: 3c8628c2b712c91f8c3958bc7e97a893cf376aaa02f4b5a1dbd5e7f14cd69418
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV also flagged this file as malicious, with ClamAV specifically identifying it as Pdf.Phishing.TtraffRobotInstall. The embedded URLs are likely used to redirect users to malicious content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://toledomarineservice.com/uploads/1/3/0/2/130271152/woribe-sesanapesokadeb-warorameken.pdf
    • http://dawux.prazskykrysarik.ru/uploads/2020/01/28/detonipopodaxi.pdf
    • http://nawabufa.klondike-gold.info/uploads/2020/01/27/fewub.pdf
    • http://thesoundmandxb.com/uploads/1/3/0/2/130289235/perimosebojavo.pdf
    • http://xel.best-prices.icu/uploads/2020/01/27/bitabok.pdf
    • http://werenuboj.rus-snow.ru/uploads/2020/01/28/figabiwep.pdf
    • http://jahtennajashkola.ru/uploads/2020/01/29/sited_wixitaj.pdf
    • http://psychotherapy121.net/uploads/1/3/0/5/130590672/74547c3475f7.pdf
    • http://palawn.com/uploads/1/3/0/5/130551677/4378020.pdf
    • http://paku.igorlucshii.online/uploads/2020/01/28/8754559.pdf
    • https://basoloniw.weebly.com/uploads/1/3/0/2/130288682/tukugofureneroxilor.pdf
    • http://jafuj.spbestonia.ru/uploads/2020/01/28/552dd6ba02cb.pdf
    • http://htools.ua/uploads/2020/01/27/sesano-gujekepa.pdf
    • https://vawirogogulop.weebly.com/uploads/1/3/0/5/130547969/8592413.pdf
    • http://weopenshows.com/uploads/1/3/0/2/130272084/130272084.html#ridge+racer+type+4+rom

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013a5.bin
3453e6001a384842c661574562588033a9771230da0bc01ed2aa2217ad2f26b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A5 8564 bytes
font_01_sfnt_off00004736.bin
b39b7001a8f9436074019f9ef4665bc1b059dffc24b0106b2299bbc47463e118
pdf-font-stream PDF embedded font (sfnt) at offset 0x4736 16468 bytes