Malicious PDF — malware analysis report

Static analysis result for SHA-256 76e1631caf338a7d…

MALICIOUS

PDF

48.0 KB Authoring application: ImageMagick First seen: 2021-01-15
MD5: 30a5b2600ff3d715ce41beb70286dce9 SHA-1: 508d96aca7221478cc5b34b6f5cf30dbc328424b SHA-256: 76e1631caf338a7d3618757eb885b0493c90057321a2f2a0cf15f6b9e2bcdf5d
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gifixasojelu.weebly.com/uploads/1/3/0/2/130270775/xomules.pdf In PDF document text
    • http://tovarioseni2.fun/uploads/2020/01/28/440b04f6b380084.pdfIn PDF document text
    • https://gerawaxojapo.weebly.com/uploads/1/3/0/5/130540128/sunafirofedinom.pdfIn PDF document text
    • https://xagorakofa.weebly.com/uploads/1/3/0/6/130604618/dokukibifi.pdfIn PDF document text
    • http://tizuwabome.psgessoibbaatend.site/uploads/2020/01/28/zazadizabinefu.pdfIn PDF document text
    • http://newcastlenetworkinggroup.com/uploads/1/3/0/5/130588444/sutegujoletuko-wozupojugegoge-fivujisime.pdfIn PDF document text
    • http://mrkellysupholstery.com/uploads/1/3/0/6/130620917/420225.pdfIn PDF document text
    • http://lujeme.veredas.online/uploads/2020/01/29/dukus_verudewilorud_dekogivuzudu.pdfIn PDF document text
    • http://janev.on-kot.ru/uploads/2020/01/28/5b10b83b.pdfIn PDF document text
    • http://vts.store/uploads/2020/01/27/425e117a64426.pdfIn PDF document text
    • http://batuzegaga.cityglush12.icu/uploads/2020/01/29/3082635.pdfIn PDF document text
    • https://zobegubitabid.weebly.com/uploads/1/3/0/2/130289204/zelexujewibipatejiv.pdfIn PDF document text
    • http://jessiedaniels.net/uploads/1/3/0/4/130489275/a7dda67b74.pdfIn PDF document text
    • http://bufeja.wesharehk.com/uploads/2020/01/28/jilisap.pdfIn PDF document text
    • http://manvs.ru/uploads/2020/01/28/xitufulujemix.pdfIn PDF document text
    • http://crompers.com/uploads/1/3/0/5/130545475/2627311.pdfIn PDF document text
    • http://xok.sportyers.com/uploads/2020/01/27/6e2e0b.pdfIn PDF document text
    • http://hidrografics.com/uploads/2020/01/27/reras-sosekuxufe-zuluf.pdfIn PDF document text
    • https://wanigunibome.weebly.com/uploads/1/3/0/5/130588799/vedusirumenada-guziv-lobizejibubota-digofiluxiw.pdfIn PDF document text
    • http://decide2evolve.com/uploads/1/3/0/5/130589334/130589334.html#game+of+thrones+bluray+free+downloadIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000161b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x161B 8776 bytes
SHA-256: 611ee411aa7d35108cc2675cd90b5d2c6a72a7869198cf4c7d42cddfc2b6cd42
font_01_sfnt_off00007368.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7368 16460 bytes
SHA-256: b6ee667f81e0c116fa796fd7fb0064e2c158f717dcb4bbd29ba118e50b0e64e5