Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d7456edf326a0d2…

MALICIOUS

PDF

76.4 KB Authoring application: Pdftk First seen: 2020-05-14
MD5: f53cf0389411fc8933b7d8f4e8ca0e94 SHA-1: 4a51b76897a955de10e4d75e8972dc5b9d3b405f SHA-256: 7d7456edf326a0d2a3419f8eefe117d710d2c3ca33abdb78b050df1a9b845988
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to other PDF files hosted on various websites. This behavior is indicative of a link farm or a distribution mechanism for further malicious content, as flagged by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV detection further support its malicious nature, classifying it as phishing or a general malware threat.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jilobogun.weebly.com/uploads/1/3/0/4/130436121/gibaxifunemirubono.pdf In PDF document text
    • https://xineluvapi.weebly.com/uploads/1/3/0/5/130540065/3991025.pdfIn PDF document text
    • http://trinitywinchestertn.org/uploads/1/3/0/4/130483741/dinivarasakij.pdfIn PDF document text
    • https://wuralijotiraw.weebly.com/uploads/1/3/0/6/130604605/muremise.pdfIn PDF document text
    • http://netuwij.find-me-2019.com/uploads/2020/01/29/445b8.pdfIn PDF document text
    • http://leadingchristianity.com/uploads/1/3/0/5/130588885/webotifomivod-segagasisato-gukixefiwodoz-puremugaxa.pdfIn PDF document text
    • http://bukawuzewo.tovarug.icu/uploads/2020/01/28/senarejaravelemano.pdfIn PDF document text
    • http://tug.omalus.com/uploads/2020/01/28/muvujubovev-wonakemido-jinesa.pdfIn PDF document text
    • http://bschealthcare.com/uploads/1/3/0/6/130621426/xaxolepopaxuropek.pdfIn PDF document text
    • http://nuzzinetwork.com/uploads/1/3/0/4/130435820/909fdf39ed226.pdfIn PDF document text
    • http://blog4girlsweebly.com/uploads/1/3/0/5/130589122/130589122.html#quest%C3%B5es+discursivas+sobre+revolu%C3%A7%C3%A3oIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001419.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1419 11100 bytes
SHA-256: 8114c620ae04a5ce716eea2b30d99c93b3d88afa2fb2d70b55e78a708def14f3
font_01_sfnt_off000052a1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x52A1 16268 bytes
SHA-256: 5d7ebd720715cd86529581f1d40cc643f68465477bd430d4be5ff736bc95f798