Malicious PDF — malware analysis report

Static analysis result for SHA-256 83636d52bc2d31cc…

MALICIOUS

PDF

44.3 KB Authoring application: Smallpdf Desktop First seen: 2020-09-24
MD5: 85f272ee41567987b9e0b59e5dddef81 SHA-1: a345b6fae4089e5fa6e7c6a9b1f855983a7eefb4 SHA-256: 83636d52bc2d31cc20fbd4c6df330be6c3a3d84ce7a429a8ba9228770ef3100b
168 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document exhibits characteristics of a phishing lure, specifically a fake invoice or payment request, as indicated by the 'SE_INVOICE_LURE' heuristic. It contains a mass of external links, with the first identified as http://conneracup.com/uploads/1/3/0/9/130969446/tipagizamiz-gugat-fofelozekuse-makulasewafotu.pdf, suggesting an attempt to redirect users to malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports its malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://conneracup.com/uploads/1/3/0/9/130969446/tipagizamiz-gugat-fofelozekuse-makulasewafotu.pdf In PDF document text
    • http://webmail.fujifilmreviews.com/uploads/1/3/0/2/130271226/pawefafatisa.pdfIn PDF document text
    • http://lenioffringa.nl/uploads/1/3/0/5/130544448/modosuma-paxok.pdfIn PDF document text
    • http://www.shirahstern.com/uploads/1/3/0/6/130639459/2646879.pdfIn PDF document text
    • http://tortugamobile.com/uploads/1/3/0/7/130739070/8816042.pdfIn PDF document text
    • http://www.killforeden.com/uploads/1/3/0/6/130603909/vinumukadixuw_goniz_wifitaburibexu.pdfIn PDF document text
    • http://getcached.com/uploads/1/3/0/7/130738831/1232295.pdfIn PDF document text
    • http://gaydisaster.net/uploads/1/3/0/5/130542902/55ed04f.pdfIn PDF document text
    • http://herbalforbloodpressure.com/uploads/1/3/0/7/130775504/7fa61d1658.pdfIn PDF document text
    • http://www.grisetti.it/uploads/1/3/0/5/130589429/4634014.pdfIn PDF document text
    • http://dgias.pl/uploads/1/3/0/2/130272903/misupeludugele-vatudi.pdfIn PDF document text
    • http://www.suly.com.au/uploads/1/3/0/6/130620268/pebitokavipokunux.pdfIn PDF document text
    • http://thelavenderdish.com/uploads/1/3/0/6/130621205/merip_ruzusodutegat_vezagaxosoze.pdfIn PDF document text
    • http://mvctk.com/uploads/1/3/0/7/130775627/811212.pdfIn PDF document text
    • http://epiphanrentals.com/uploads/1/3/0/4/130483271/4825589.pdfIn PDF document text
    • http://www.grannyfarkel.com/uploads/1/3/0/5/130551475/furan.pdfIn PDF document text
    • http://leemarksafety.co/uploads/1/3/0/6/130639868/e1b0230c15.pdfIn PDF document text
    • http://shaydanielleesthetics.com/uploads/1/3/0/4/130483770/ritotijurig-xovakuw.pdfIn PDF document text
    • http://joeysjoeyssugargliders.com/uploads/1/3/0/4/130488698/865fc6f03097da6.pdfIn PDF document text
    • http://www.youngwordsmiths.club/uploads/1/3/0/5/130588779/9c4e1a51e0.pdfIn PDF document text
    • http://www.orkneymatrix.co.uk/uploads/1/3/0/2/130271081/vuvulukimaretigumona.pdfIn PDF document text
    • http://jf1850.com/uploads/1/3/0/7/130739011/zotitu.pdfIn PDF document text
    • http://74-123-77-82.mgwnet.com/uploads/1/3/0/6/130603776/130603776.html#sage+simply+accounting+tutorialIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003384.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3384 16204 bytes
SHA-256: f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
font_01_sfnt_off00004b6d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4B6D 8056 bytes
SHA-256: 001cf86c0a0907d4e4e79a7282313a56564d787e3c698fe908fe275f60a1fb5c