Malicious PDF — malware analysis report

Static analysis result for SHA-256 437c87fb7c088e02…

MALICIOUS

PDF

42.4 KB Authoring application: Solid Converter PDF First seen: 2020-09-24
MD5: 7138756a759ca4a8a3386f261289ddc4 SHA-1: b334a8a0c5e3468b6eee783bd97e29656cfe8117 SHA-256: 437c87fb7c088e02e052ebec379817588c84038a9341676b25f73477ad107b90
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic, which is indicative of a link farm or phishing campaign. The SE_INVOICE_LURE heuristic further suggests a social engineering pretext related to payments or invoices. The ClamAV detection confirms the malicious nature of the file. The embedded links likely lead to further malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mnnewfs.com/uploads/1/3/0/6/130639307/5440339.pdf In PDF document text
    • http://newparanormalsociety.com/uploads/1/3/0/5/130542829/46089bc17b.pdfIn PDF document text
    • http://shoalcreekinteriors.com/uploads/1/3/0/6/130620745/1566738.pdfIn PDF document text
    • http://baytowntreeservices.com/uploads/1/3/0/3/130323952/nenafuniwere.pdfIn PDF document text
    • http://sam-miee.com/uploads/1/3/0/6/130621220/3bd42eb0d.pdfIn PDF document text
    • http://playpass.net/uploads/1/3/0/2/130289305/kakoni-jafajoka-futinuxitukuxin.pdfIn PDF document text
    • http://chasnat.weebly.com/uploads/1/3/0/6/130620685/36a5de3.pdfIn PDF document text
    • http://windsorplaceepsom.com/uploads/1/3/0/3/130323814/2235593.pdfIn PDF document text
    • http://bartolomeilaw.com/uploads/1/3/0/4/130488286/130488286.html#child+support+guidelines+tennessee+calculatorIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011bc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11BC 8484 bytes
SHA-256: 56439f70fbe8749722674532624754df62470540ca6bc57bbc0a5f2658d65e33
font_01_sfnt_off00006afa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6AFA 2668 bytes
SHA-256: bb66d78edca8aa75a8db461931e44ad6eab12e4cd439df836d92d13c6ef6c22d