Malicious PDF — malware analysis report

Static analysis result for SHA-256 4beb38fce9fef6ba…

MALICIOUS

PDF

36.6 KB Authoring application: OpenOffice Draw First seen: 2020-09-15
MD5: d5d8430c67e9e51ac1d133391f5c1e05 SHA-1: 2e76c31cb3dee3eefe093d275513c102be69fb12 SHA-256: 4beb38fce9fef6ba99a6dffb67d00182226c2b5abd3156fa7c82c16e484d5914
212 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF file contains a large number of embedded links to other PDF files, suggesting a link farm or SEO abuse tactic. It also instructs the user to disable security software, a common lure in phishing attacks. The document impersonates a signing service to trick the user into downloading and potentially executing further malicious content. No scripts were extracted, but the embedded URLs are the primary indicators of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Security software disable instruction high SE_SECURITY_BYPASS
    Document instructs the user to disable antivirus or security software — unusual for ordinary documents and high-risk in an unsolicited file
  • Document signing service impersonation lure medium SE_DOCUSIGN_LURE
    Document impersonates DocuSign, Adobe Sign, or a similar signing service in a signing-request context
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://liquorlawsvt.com/uploads/1/3/0/5/130588579/tuxaxo-nimubatumejabod.pdf In PDF document text
    • http://konceptdev.net/uploads/1/3/0/7/130739502/sorejepikejipepij.pdfIn PDF document text
    • http://www.star-nrg.com/uploads/1/3/0/7/130776720/c34b260920df73.pdfIn PDF document text
    • http://mta-sts.mx.joangraham.com/uploads/1/3/0/5/130590555/temejoged.pdfIn PDF document text
    • http://misssampson.com/uploads/1/3/0/2/130274258/5531867.pdfIn PDF document text
    • http://stakemycoin.com/uploads/1/3/0/3/130313619/3110192.pdfIn PDF document text
    • http://www.amethystdreams.com.au/uploads/1/3/0/7/130739746/1be8c0b.pdfIn PDF document text
    • http://christinecarson.net/uploads/1/3/0/5/130590714/f677149e993fb06.pdfIn PDF document text
    • http://mikesfamoussteaksandsubs.com/uploads/1/3/0/3/130323724/8996766.pdfIn PDF document text
    • http://authorjulievail.com/uploads/1/3/0/2/130288986/5266bf8ae.pdfIn PDF document text
    • http://atlantadentalanesthesia.com/uploads/1/3/0/3/130379612/1506728.pdfIn PDF document text
    • http://woodridgemusicclub.com/uploads/1/3/0/7/130738875/9026722.pdfIn PDF document text
    • http://hope4womeninternational.com/uploads/1/3/0/7/130776069/ritiburajafo.pdfIn PDF document text
    • http://bendavidsonministries.com/uploads/1/3/0/4/130488983/gagewituzov.pdfIn PDF document text
    • http://shopprayhustleslay.com/uploads/1/3/0/4/130477176/muxuduwolemuwuragi.pdfIn PDF document text
    • http://just4owens.com/uploads/1/3/0/7/130775950/nudefapixodebaf.pdfIn PDF document text
    • http://powerwashsystems.net/uploads/1/3/0/4/130476587/jazobo_mipegumoz_xeruve_zewumibobefu.pdfIn PDF document text
    • http://the-well.net/uploads/1/3/0/5/130590507/xasote-ganenixe.pdfIn PDF document text
    • http://www.comengetboothed.com.au/uploads/1/3/0/6/130639309/637198.pdfIn PDF document text
    • http://christopherwyand.com/uploads/1/3/0/5/130590770/nuwenefuguk.pdfIn PDF document text
    • http://862.bpmtc.com/uploads/1/3/0/8/130813979/130813979.html#adobe+acrobat+reader+pro+dc+gratisIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f80.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2F80 7852 bytes
SHA-256: b975318b5fe8d450f3e5cee23461d3faa153cd7bf0359348009961b607725699