Malicious PDF — malware analysis report

Static analysis result for SHA-256 6a4d209fd409530a…

MALICIOUS

PDF

42.2 KB Authoring application: PDFBox
MD5: 666fc77f165c4757de84b06d36371cf4 SHA-1: 71b25aeb76b842aa220d01765acb61d2ecd03056 SHA-256: 6a4d209fd409530a0cf9e790f1149d70cdfcffdba5a32ed2e0f2c1e0c9ea784e
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, which is a common technique for SEO poisoning or phishing campaigns. The heuristic 'PDF_SEO_LINK_FARM' and the ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly indicate malicious intent. The presence of embedded URLs suggests an attempt to redirect users to malicious content, potentially for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fmark.com/uploads/1/3/0/5/130551416/lasalewasogurup.pdf
    • http://www.server1.doneitnow.com/uploads/1/3/0/7/130776727/podex_jajiteragule_jitikepub_kapinekimofaxa.pdf
    • http://naruebordin.com/uploads/1/3/0/5/130539497/1095173.pdf
    • http://countrymusicpromo.com/uploads/1/3/0/3/130324203/2790bdfc2d1.pdf
    • http://republicfenceco.net/uploads/1/3/0/8/130873741/gaxefuvix.pdf
    • http://lucky13lawncare.com/uploads/1/3/0/5/130550778/gupozodud.pdf
    • http://atoz2019.ca/uploads/1/3/0/6/130621457/8429844.pdf
    • http://3324user72cba-ckd.com/uploads/1/3/0/9/130969057/vawisopijipukekoto.pdf
    • http://younggunsfishingteam.com/uploads/1/3/0/4/130435729/1231646.pdf
    • http://sightlux.info/uploads/1/3/0/2/130272847/9e4a2b3591d6f57.pdf
    • http://stewthompson2.com/uploads/1/3/0/5/130588635/f6b6cea4e8.pdf
    • http://nw7.me/uploads/1/3/0/7/130776741/javopukipub.pdf
    • http://thecurlwhispererchi.com/uploads/1/3/0/5/130539554/65902838df5e6.pdf
    • http://northeastfjord.com/uploads/1/3/0/6/130604785/742df3.pdf
    • http://subudappid.org/uploads/1/3/0/6/130639607/pekagajolarunit-zizora-dosobesijez.pdf
    • http://citizensforbaringer.com/uploads/1/3/0/7/130776413/duniwemerawu-werimiwaluza-bulimidajewow.pdf
    • http://theordinaryvoter.com/uploads/1/3/0/7/130776599/845258.pdf
    • http://rubykwon.com/uploads/1/3/0/6/130603682/5035439.pdf
    • http://myedmontonaccountants.com/uploads/1/3/0/5/130589241/9215eed2ca4.pdf
    • http://psychotherapyportland.net/uploads/1/3/0/7/130776219/3999938.pdf
    • http://jjsholdings.net/uploads/1/3/0/5/130588185/xebatu.pdf
    • http://crystalclearings.com/uploads/1/3/0/3/130323151/zatelutukawuk_lagitopu.pdf
    • http://cafecancun.us/uploads/1/3/0/4/130476859/7267613.pdf
    • http://burchlangstaff.com/uploads/1/3/0/7/130738739/130738739.html#young%27s+modulus+tensile+strength
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000034d1.bin
5743b3b6a1e05848463bba8b08d08ab32065d274b8801f7939bb119dbd972f71
pdf-font-stream PDF embedded font (sfnt) at offset 0x34D1 3068 bytes
font_01_sfnt_off00004210.bin
7a8892b371f6dc30446ba289f0de93425b797569e98b51f1dff62f205072e0a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x4210 8540 bytes