Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c27048ecdab8583…

MALICIOUS

PDF

38.2 KB Authoring application: Karbon First seen: 2021-02-18
MD5: f2084cbe14ad727b8366dd8e02d62c4e SHA-1: 59e697e5d67de1a55f4074270813ea2d8146c2cd SHA-256: 6c27048ecdab858398d65ea6d656350b0dab46e24bb7c8fec7d4edf8fb5bc6f0
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ponafugi.expertmagnit.ru/uploads/2020/01/28/xarafuli.pdf In PDF document text
    • http://motomomfuel.com/uploads/1/3/0/3/130323115/kawer.pdfIn PDF document text
    • http://shopdochoi.tech/uploads/2020/01/28/nedulofowajo.pdfIn PDF document text
    • http://tomakeandtobe.com/uploads/1/3/0/5/130539319/fe3e5afae1.pdfIn PDF document text
    • http://theautismhelpgroup.com/uploads/1/3/0/6/130620173/vanikenenigiwiw.pdfIn PDF document text
    • http://nylarose.co/uploads/1/3/0/3/130313836/5586065.pdfIn PDF document text
    • http://wendyohlendorf.com/uploads/1/3/0/6/130621542/9072017.pdfIn PDF document text
    • http://ximi.likeforinsta.xyz/uploads/2020/01/29/2605165.pdfIn PDF document text
    • http://dosunuk.javanotepad.com/uploads/2020/01/28/pofeluxuxewaj.pdfIn PDF document text
    • http://mybellacouture.com/uploads/1/3/0/6/130621683/segawawe-gavimurin-womenunolule-vusasez.pdfIn PDF document text
    • http://mykarl.info/uploads/1/3/0/6/130621642/45d27b8b92ed2.pdfIn PDF document text
    • http://mipalmi.com/uploads/1/3/0/4/130494743/govuzawapi.pdfIn PDF document text
    • http://art2artexhibitions.com/uploads/1/3/0/5/130588856/130588856.html#spanish+english+false+cognates+list+pdfIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001b07.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B07 9024 bytes
SHA-256: 0136696de02a3333fd3cea59138c398562867f83b9347d3124cd749b1f5e0a3f