Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d0edcc1db27650c…

MALICIOUS

PDF

36.2 KB Authoring application: SWFTools First seen: 2020-09-24
MD5: de1aa71a434885492596c56a9c4ab1d9 SHA-1: 82fa79a1343b806c29f7b4485216f48cb992c5d7 SHA-256: 7d0edcc1db27650ce03f11a55da02438591fcdc272e36850c8c2f3efed447db3
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, detected as a PDF_SEO_LINK_FARM. This technique is often used to distribute malicious content or manipulate search engine rankings. While no scripts were explicitly extracted, the heuristic SE_LOLBIN_RUN_COMMAND suggests potential command execution, and the ClamAV detection as Pdf.Phishing.TtraffRobotInstall-7605656-0 further supports a phishing or malicious distribution intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://3bqdiamondkidz.com/uploads/1/3/0/6/130620482/tizux_lorifijifom_tabefasawajo_lotosusef.pdf In PDF document text
    • http://aux3ponts.com/uploads/1/3/0/3/130323633/7b8d7a3719.pdfIn PDF document text
    • http://shaglife.com/uploads/1/3/0/6/130639616/ff60b79.pdfIn PDF document text
    • http://melangeemporium.com/uploads/1/3/0/5/130543985/fc2e0491a03f4.pdfIn PDF document text
    • http://innsbrookcitycenter.net/uploads/1/3/0/6/130603673/xemafu-rujaxu-bosenu-wumopales.pdfIn PDF document text
    • http://mta-sts.mail.yourchoicepettransport.com/uploads/1/3/0/6/130604209/5636575.pdfIn PDF document text
    • http://www.cosmetictattoostudio.com/uploads/1/3/0/2/130287302/givorimirezigukube.pdfIn PDF document text
    • http://paintinghopefoundation.com/uploads/1/3/0/7/130776516/ruvizomep.pdfIn PDF document text
    • http://michelehrose.com/uploads/1/3/0/6/130620788/0765eb.pdfIn PDF document text
    • http://officialgoodboys.club/uploads/1/3/0/4/130488345/2310190.pdfIn PDF document text
    • http://www.woodwerx.net/uploads/1/3/0/6/130604166/2557952.pdfIn PDF document text
    • http://hostmaster.vanessadrew.com/uploads/1/3/0/7/130740502/5249999.pdfIn PDF document text
    • http://bobselectric.co.uk/uploads/1/3/0/6/130604152/38d082488.pdfIn PDF document text
    • http://hostmaster.cockapoorescuegb.org/uploads/1/3/0/5/130551775/9090601.pdfIn PDF document text
    • http://railandrivermarket.com/uploads/1/3/0/7/130738913/2832284.pdfIn PDF document text
    • http://jinwonhanglass.com/uploads/1/3/0/5/130588714/2830752.pdfIn PDF document text
    • http://britanynavarretephotography.com/uploads/1/3/0/7/130775683/8dfc7c03.pdfIn PDF document text
    • http://fallasleepblog.com/uploads/1/3/0/7/130776269/fepave_melawasawuge_zunoxadixoram_vefewavol.pdfIn PDF document text
    • http://picacookie.com/uploads/1/3/0/6/130621060/3240576.pdfIn PDF document text
    • http://host175.carmichaelnl.com/uploads/1/3/0/3/130323811/130323811.html#online+reading+comprehension+games+for+3rd+gradeIn PDF document text
🗂 Part of campaign: jinwonhanglass.com 4 samples

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002e8a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2E8A 7916 bytes
SHA-256: 7dab268f20c710d83dce0dc5e15d3d48b5334824aff5beca4819ca2817072fae