Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ed5fc2c984a8591…

MALICIOUS

PDF

44.7 KB Authoring application: QPDF First seen: 2020-09-24
MD5: 1dca901fad5109275612b62f1f204a33 SHA-1: 9c117c8fc1f9396582163b2182c5436c1b977699 SHA-256: 4ed5fc2c984a8591295e3f6d7fd5eefb632fa7c59979f392e27438c8f853fd04
192 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains a large number of external links, characteristic of a SEO link farm, and is detected by ClamAV as Pdf.Phishing.TtraffRobotInstall. The document body suggests a social-engineering lure, instructing the user to install a browser extension or update to view content. This indicates the primary goal is to trick the user into executing malicious code or downloading further malware. The embedded URLs likely serve as landing pages for this lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://raxami.moscowhome-realty.ru/uploads/2020/01/28/rijojepizari.pdf In PDF document text
    • http://clear-home-solutions.com/uploads/1/3/0/6/130621581/vuwolizenizoruv_sokamenif_fomegitezowaxi.pdfIn PDF document text
    • http://donilegend.com/uploads/1/3/0/5/130543084/lixug-govujefezuz-radan.pdfIn PDF document text
    • http://cestagift.com/uploads/1/3/0/3/130379311/xejerizetigasaz.pdfIn PDF document text
    • http://nourishmentinmotion.com/uploads/1/3/0/5/130590777/xifipigo.pdfIn PDF document text
    • http://ssunitedstatesreef.com/uploads/1/3/0/6/130621642/02ef1d74331a0.pdfIn PDF document text
    • http://mmtaxandfinancial.com/uploads/1/3/0/4/130476814/vigopajabewedibus.pdfIn PDF document text
    • http://myidahoinsure.com/uploads/1/3/0/4/130477613/d1dc69f1ed0b4.pdfIn PDF document text
    • http://nashobavalleyextractco.com/uploads/1/3/0/6/130639413/130639413.html#grid+template+repeat+autoIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001215.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1215 8608 bytes
SHA-256: 6ab3459b13e8392058fead0036d954d1422b0997540171e6ede65fd6afd349a9
font_01_sfnt_off00006ac6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6AC6 1960 bytes
SHA-256: 3c2e106de6cb787409ee9e7a468dbada390938761ac748b466265f884e05639f
font_02_sfnt_off000073c3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x73C3 2652 bytes
SHA-256: 1b3f82cd74c5b6671cc0c0d4a6c7877b74bb57ca469b2a61ef541918e41af838