Malicious PDF — malware analysis report

Static analysis result for SHA-256 69f9d4f8033e5a14…

MALICIOUS

PDF

61.4 KB Authoring application: SWFTools
MD5: 54617d31d4e83c0593d253304c9b6bf6 SHA-1: 94fdef68a213abf944dbe54857fb396c7b1944b7 SHA-256: 69f9d4f8033e5a1426c9efdc155244320065a14e268f40cd4212a053077063b8
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs pointing to external PDF documents, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. This suggests a tactic to manipulate search engine results or to distribute additional malicious content. The ClamAV detection and ML classifier further support its malicious nature. The embedded URLs are the primary IOCs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mail.bestpropertyph.com/uploads/1/3/0/4/130488286/4745218.pdf
    • http://springvillehighblt.org/uploads/1/3/0/6/130639296/7835580.pdf
    • http://vhcministry.org/uploads/1/3/0/6/130639851/9920297.pdf
    • http://mygametruckcostamesa.com/uploads/1/3/0/4/130476548/4357828.pdf
    • http://iamalexandro.com/uploads/1/3/0/4/130483769/xuxus.pdf
    • http://www.hardestyengineering.com/uploads/1/3/0/4/130483770/sodovona.pdf
    • http://bread.healmarketplace.com/uploads/1/3/0/4/130483286/mipijawutani.pdf
    • http://sceneguide.net/uploads/1/3/0/7/130775797/wapolaleki.pdf
    • http://www.theoldmessrooms.co.uk/uploads/1/3/0/4/130478307/gatavux.pdf
    • http://kinzerfarms.com/uploads/1/3/0/5/130551239/gezul.pdf
    • http://manofaran.net/uploads/1/3/0/6/130620524/solimebovojedop.pdf
    • http://44michigan.com/uploads/1/3/0/5/130540296/e5a44bd3ea86200.pdf
    • http://alldayhiphop.com/uploads/1/3/0/5/130588568/gakuraw.pdf
    • http://naviencehairco.com/uploads/1/3/0/8/130874563/9bbe4c.pdf
    • http://holypost.net/uploads/1/3/0/4/130491001/6145190.pdf
    • http://dralanlogan.com/uploads/1/3/0/7/130739686/jasizekezazud-bofuvi-nebebawim-ruzuvutesita.pdf
    • http://northstreetshoppes.com/uploads/1/3/0/3/130323211/f3e06ad45b592.pdf
    • http://mx.godsword4u.com/uploads/1/3/0/7/130740391/4a4914169ab6.pdf
    • http://christinescott.info/uploads/1/3/0/7/130776388/8674047.pdf
    • http://miztcomedy.com/uploads/1/3/0/4/130488163/c8493a26.pdf
    • http://wecreatewebsites.org/uploads/1/3/0/4/130489297/6184039.pdf
    • http://msaimports.com/uploads/1/3/0/2/130288341/vulebavuvoz-zefoz-bozilej-daduliremasewa.pdf
    • http://food.ashleymartinportfolio.com/uploads/1/3/0/6/130639744/130639744.html#population+ecology+begon+pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001045.bin
c95f7cc1f5e8746df266327aba70242d225e24263480d528ec99173c0aa68a56
pdf-font-stream PDF embedded font (sfnt) at offset 0x1045 9288 bytes
font_01_sfnt_off00008ab0.bin
97a445e4638c7b493057f1a24513c1abef2abc2cf7b9a8cf6cb11e400ba08a33
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AB0 16156 bytes
font_02_sfnt_off00009fe1.bin
a68149e620e5654b8a4515046d30d8708f571ab3368d393574efe1b1a64beef8
pdf-font-stream PDF embedded font (sfnt) at offset 0x9FE1 4316 bytes