Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c8ed21011275907…

MALICIOUS

PDF

40.3 KB Authoring application: Scribus
MD5: cdcd3c305997451affd37c8160615c01 SHA-1: cf1ce5fb9d56ec7eddad606059f02301f4c682af SHA-256: 3c8ed21011275907c2e7b83e93600bbcaf05fadcb967333a79d602df5a970cd4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to other PDF files hosted on various domains. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution. No scripts were extracted, but the structure of the PDF and the embedded URLs are sufficient to determine the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://soilnstruments.com/uploads/1/3/0/7/130740250/nurupiwefo.pdf
    • http://northernlightshockeynj.com/uploads/1/3/0/7/130738966/lerifezup.pdf
    • http://nextbillionventures.com/uploads/1/3/0/2/130272600/4500537.pdf
    • http://disdiy.com/uploads/1/3/0/6/130604756/tuvagumefasoguz.pdf
    • http://jtmarketingsvs.com/uploads/1/3/0/2/130271211/duxexeguwoxagu_wekujunom_kozaduvagodus_lipasore.pdf
    • http://mibisho.net/uploads/1/3/0/7/130738914/vofiworoniluba_rasapenaxeju.pdf
    • http://nkfanexperience.com/uploads/1/3/0/4/130488229/0b2bdefab6f71.pdf
    • http://puzzlesforprogress.com/uploads/1/3/0/5/130551330/duniran-kizosobu.pdf
    • http://nathansdetailing.net/uploads/1/3/0/6/130639885/tupewoda.pdf
    • http://hyper-metrix.net/uploads/1/3/0/5/130551166/0b2858bd218d.pdf
    • http://wikiteras.vipiski-online.icu/uploads/2020/01/28/92cffc8f548fa3.pdf
    • http://relianceauto.org/uploads/1/3/0/6/130639588/latavasumeveme.pdf
    • http://adayofhope.co/uploads/1/3/0/7/130739067/130739067.html#how+to+convert+a+excel+spreadsheet+to+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001360.bin
6cd5f805c154c64b67fc77f4ffbfb9c5e0d93d0a7b36c048e0df8c882c7b5a88
pdf-font-stream PDF embedded font (sfnt) at offset 0x1360 7712 bytes
font_01_sfnt_off0000622b.bin
83d89f79375f7f339e88070a8779324ce221c94923bff415e388e162fbc46cfe
pdf-font-stream PDF embedded font (sfnt) at offset 0x622B 2604 bytes