Malicious PDF — malware analysis report

Static analysis result for SHA-256 6a4d209fd409530a…

MALICIOUS

PDF

42.2 KB Authoring application: PDFBox First seen: 2020-09-04
MD5: 666fc77f165c4757de84b06d36371cf4 SHA-1: 71b25aeb76b842aa220d01765acb61d2ecd03056 SHA-256: 6a4d209fd409530a0cf9e790f1149d70cdfcffdba5a32ed2e0f2c1e0c9ea784e
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, which is a common technique for SEO poisoning or phishing campaigns. The heuristic 'PDF_SEO_LINK_FARM' and the ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly indicate malicious intent. The presence of embedded URLs suggests an attempt to redirect users to malicious content, potentially for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fmark.com/uploads/1/3/0/5/130551416/lasalewasogurup.pdf In PDF document text
    • http://www.server1.doneitnow.com/uploads/1/3/0/7/130776727/podex_jajiteragule_jitikepub_kapinekimofaxa.pdfIn PDF document text
    • http://naruebordin.com/uploads/1/3/0/5/130539497/1095173.pdfIn PDF document text
    • http://countrymusicpromo.com/uploads/1/3/0/3/130324203/2790bdfc2d1.pdfIn PDF document text
    • http://republicfenceco.net/uploads/1/3/0/8/130873741/gaxefuvix.pdfIn PDF document text
    • http://lucky13lawncare.com/uploads/1/3/0/5/130550778/gupozodud.pdfIn PDF document text
    • http://atoz2019.ca/uploads/1/3/0/6/130621457/8429844.pdfIn PDF document text
    • http://3324user72cba-ckd.com/uploads/1/3/0/9/130969057/vawisopijipukekoto.pdfIn PDF document text
    • http://younggunsfishingteam.com/uploads/1/3/0/4/130435729/1231646.pdfIn PDF document text
    • http://sightlux.info/uploads/1/3/0/2/130272847/9e4a2b3591d6f57.pdfIn PDF document text
    • http://stewthompson2.com/uploads/1/3/0/5/130588635/f6b6cea4e8.pdfIn PDF document text
    • http://nw7.me/uploads/1/3/0/7/130776741/javopukipub.pdfIn PDF document text
    • http://thecurlwhispererchi.com/uploads/1/3/0/5/130539554/65902838df5e6.pdfIn PDF document text
    • http://northeastfjord.com/uploads/1/3/0/6/130604785/742df3.pdfIn macro / runtime command snippet
    • http://subudappid.org/uploads/1/3/0/6/130639607/pekagajolarunit-zizora-dosobesijez.pdfIn macro / runtime command snippet
    • http://citizensforbaringer.com/uploads/1/3/0/7/130776413/duniwemerawu-werimiwaluza-bulimidajewow.pdfIn PDF document text
    • http://theordinaryvoter.com/uploads/1/3/0/7/130776599/845258.pdfIn PDF document text
    • http://rubykwon.com/uploads/1/3/0/6/130603682/5035439.pdfIn PDF document text
    • http://myedmontonaccountants.com/uploads/1/3/0/5/130589241/9215eed2ca4.pdfIn PDF document text
    • http://psychotherapyportland.net/uploads/1/3/0/7/130776219/3999938.pdfIn PDF document text
    • http://jjsholdings.net/uploads/1/3/0/5/130588185/xebatu.pdfIn PDF document text
    • http://crystalclearings.com/uploads/1/3/0/3/130323151/zatelutukawuk_lagitopu.pdfIn PDF document text
    • http://cafecancun.us/uploads/1/3/0/4/130476859/7267613.pdfIn PDF document text
    • http://burchlangstaff.com/uploads/1/3/0/7/130738739/130738739.html#young%27s+modulus+tensile+strengthIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000034d1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x34D1 3068 bytes
SHA-256: 5743b3b6a1e05848463bba8b08d08ab32065d274b8801f7939bb119dbd972f71
font_01_sfnt_off00004210.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4210 8540 bytes
SHA-256: 7a8892b371f6dc30446ba289f0de93425b797569e98b51f1dff62f205072e0a9