Malicious PDF — malware analysis report

Static analysis result for SHA-256 437c87fb7c088e02…

MALICIOUS

PDF

42.4 KB Authoring application: Solid Converter PDF
MD5: 7138756a759ca4a8a3386f261289ddc4 SHA-1: b334a8a0c5e3468b6eee783bd97e29656cfe8117 SHA-256: 437c87fb7c088e02e052ebec379817588c84038a9341676b25f73477ad107b90
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which is indicative of a link farm or phishing campaign. The SE_INVOICE_LURE heuristic further suggests a social engineering pretext related to payments or invoices. The ClamAV detection confirms the malicious nature of the file. The embedded links likely lead to further malicious content or phishing pages.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mnnewfs.com/uploads/1/3/0/6/130639307/5440339.pdf
    • http://newparanormalsociety.com/uploads/1/3/0/5/130542829/46089bc17b.pdf
    • http://shoalcreekinteriors.com/uploads/1/3/0/6/130620745/1566738.pdf
    • http://baytowntreeservices.com/uploads/1/3/0/3/130323952/nenafuniwere.pdf
    • http://sam-miee.com/uploads/1/3/0/6/130621220/3bd42eb0d.pdf
    • http://playpass.net/uploads/1/3/0/2/130289305/kakoni-jafajoka-futinuxitukuxin.pdf
    • http://chasnat.weebly.com/uploads/1/3/0/6/130620685/36a5de3.pdf
    • http://windsorplaceepsom.com/uploads/1/3/0/3/130323814/2235593.pdf
    • http://bartolomeilaw.com/uploads/1/3/0/4/130488286/130488286.html#child+support+guidelines+tennessee+calculator

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011bc.bin
56439f70fbe8749722674532624754df62470540ca6bc57bbc0a5f2658d65e33
pdf-font-stream PDF embedded font (sfnt) at offset 0x11BC 8484 bytes
font_01_sfnt_off00006afa.bin
bb66d78edca8aa75a8db461931e44ad6eab12e4cd439df836d92d13c6ef6c22d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AFA 2668 bytes