Malicious PDF — malware analysis report

Static analysis result for SHA-256 6893908b6fb0808a…

MALICIOUS

PDF

39.0 KB Authoring application: Solid Converter PDF First seen: 2021-01-23
MD5: 5d765a43f825434f736f656d11b709d6 SHA-1: 0a2b894bb032a7f7cb3b79fa7ee11e3061a2b0fd SHA-256: 6893908b6fb0808a0deedaf98b817283c7488b499c42de2c103237f4586b281f
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sit.supermassive.agency/uploads/2020/01/28/kirelaz.pdf In PDF document text
    • http://thejoyofjob.com/uploads/1/3/0/3/130312926/3319110.pdfIn PDF document text
    • http://nuluxazo.vipdating.icu/uploads/2020/01/28/wabonopikofanev.pdfIn PDF document text
    • http://pup.remont-apple1.icu/uploads/2020/01/28/vujivaf.pdfIn PDF document text
    • https://bekowonid.weebly.com/uploads/1/3/0/5/130543366/jukamedibi.pdfIn PDF document text
    • http://pejikezim.homka.online/uploads/2020/01/27/wudulidadapemo-zodejorexuli-jazumawakiki.pdfIn PDF document text
    • http://sandcastletreasures.com/uploads/1/3/0/6/130639593/8419597.pdfIn PDF document text
    • http://pane.bestjournal.ru/uploads/2020/01/29/lufobizulejigix-xedusibek.pdfIn PDF document text
    • http://theplugalex.com/uploads/1/3/0/4/130435876/8696756.pdfIn PDF document text
    • http://vodis.iraway.com/uploads/2020/01/28/nanutajanozo.pdfIn PDF document text
    • http://ancientcraftstudio.com/uploads/1/3/0/5/130551106/risivimiravi-ziwutosejavuta-gabol.pdfIn PDF document text
    • http://soyana.ru/uploads/2020/01/27/4726808.pdfIn PDF document text
    • http://brandmediax.com/uploads/1/3/0/5/130539654/bojomuselagano_polaselopajije_zuwiwudetaruf.pdfIn PDF document text
    • http://memijo.sell-video.ru/uploads/2020/01/28/66b1820d4a.pdfIn PDF document text
    • http://ledilolli.com/uploads/2020/01/27/c9ea7a.pdfIn PDF document text
    • http://video-review24.info/uploads/2020/01/29/6f1468.pdfIn PDF document text
    • https://dasejawememe.weebly.com/uploads/1/3/0/4/130489131/f07a9.pdfIn PDF document text
    • http://lisaruth.net/uploads/1/3/0/6/130621785/buredafonu.pdfIn PDF document text
    • http://grandcentraltradingcompany.com/uploads/1/3/0/5/130588964/zagefulu.pdfIn PDF document text
    • http://alicanteapoyopsicologia.org/uploads/1/3/0/6/130621689/fukedugi-jired-kozalunowajole-kimiga.pdfIn PDF document text
    • http://rostelekomu.fun/uploads/2020/01/28/magebofotapi_zukuvomolol.pdfIn PDF document text
    • http://kulalutej.cityglush7.icu/uploads/2020/01/27/232664.pdfIn PDF document text
    • http://kuhni-msc07.icu/uploads/2020/01/28/rixuzo.pdfIn PDF document text
    • http://analysisoftheatre.org/uploads/1/3/0/2/130272582/2083172.pdfIn PDF document text
    • http://bretagne-cmb.com/uploads/2020/01/27/pumifagexurodutubuko.pdfIn PDF document text
    • http://mtziongoshen.church/uploads/1/3/0/5/130539438/130539438.html#blue+monday+fats+domino+piano+sheet+musicIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017da.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17DA 8700 bytes
SHA-256: 324f12fc824e1f9722844957a4f2c1f193c4260175da573f5f5298995f651c17