Malicious PDF — malware analysis report

Static analysis result for SHA-256 6718c0c0f5fbe494…

MALICIOUS

PDF

32.7 KB Authoring application: PDFBox First seen: 2021-01-23
MD5: 14ca179f465f1763283a3d6964fddac0 SHA-1: 031df6b1c2c71faf890ce5aaf3193d31d67bb409 SHA-256: 6718c0c0f5fbe494ec2290e881ade4de718ae0332c097b5fd176be82544cd710
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://upfrontadds.com/uploads/1/3/0/6/130640090/begiluren-najeb.pdf In PDF document text
    • http://latotuxigu.storefb.xyz/uploads/2020/01/28/1421113.pdfIn PDF document text
    • http://son.mktrade.org/uploads/2020/01/29/kemowikamevavik_noferononefab_wudabixuribulun_rofarusivixonij.pdfIn PDF document text
    • http://faxibu.original-brand.pro/uploads/2020/01/28/1f2817.pdfIn PDF document text
    • http://dphiehsu.weebly.com/uploads/1/3/0/5/130588336/3417690.pdfIn PDF document text
    • http://abcpreschoolcville.com/uploads/1/3/0/5/130539768/fuwesibolifu_nibafija_jemenunaligim_zeriz.pdfIn PDF document text
    • https://xuvalisunoz.weebly.com/uploads/1/3/0/2/130270879/2661488.pdfIn PDF document text
    • http://lampalounge.ru/uploads/2020/01/29/6421022.pdfIn PDF document text
    • http://roradafev.csgo-bet.ru/uploads/2020/01/27/3953025.pdfIn PDF document text
    • http://matthewsingerucla.com/uploads/1/3/0/2/130287229/e096bf54bea77b.pdfIn PDF document text
    • http://ganu.imperium.bz/uploads/2020/01/27/mabemuj_futoxep_sagar_jovorij.pdfIn PDF document text
    • http://sweetsonsticks.com/uploads/1/3/0/5/130589435/4547610.pdfIn PDF document text
    • http://2ourhealth.net/uploads/1/3/0/4/130483520/tekilopulilorewu.pdfIn PDF document text
    • http://micasitarentals.com/uploads/1/3/0/6/130604949/130604949.html#activity+diagram+example+with+explanation+pdfIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001510.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1510 7276 bytes
SHA-256: 8d41f69f3f788db48a0004f323494799624248b6a5720828e0787b44ac311727