Malicious PDF — malware analysis report

Static analysis result for SHA-256 854a0601e2008c1a…

MALICIOUS

PDF

96.7 KB Authoring application: Scribus First seen: 2020-09-24
MD5: d1d5bc7e0b8e05874b99fba38db31f44 SHA-1: fde288a8af100ba92dc6e4afb8174f26b035f800 SHA-256: 854a0601e2008c1a9c74dbfdbc1261bf4e3911335ec76602ec2ad160e6dec79d
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links likely point to other PDF documents hosted on various domains, suggesting a tactic to manipulate search engine results or distribute further malicious content. The ML classifier and ClamAV detection strongly support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://myfloridaec.org/uploads/1/3/0/7/130739162/60a993b60a6e.pdf In PDF document text
    • http://neverreacttohate.com/uploads/1/3/0/6/130639607/8221851.pdfIn PDF document text
    • http://callihanenglish.com/uploads/1/3/0/3/130379081/2550f82.pdfIn PDF document text
    • http://choicecutengraving.com/uploads/1/3/0/5/130590482/645154.pdfIn PDF document text
    • http://cosy-home.org/uploads/1/3/0/6/130605259/7e5032ddb9b8044.pdfIn PDF document text
    • http://poshha.net/uploads/1/3/0/7/130740456/7097173.pdfIn PDF document text
    • http://lavacationrentals.net/uploads/1/3/0/6/130639994/negevebanogoxi-wurarajudajox-sevofaroge-paketimepowo.pdfIn PDF document text
    • http://westlandpropertymanagers.com/uploads/1/3/0/7/130738578/vilosuxulefexexigaw.pdfIn PDF document text
    • http://hostmaster.honeypotcreativecafe.com/uploads/1/3/0/6/130639513/jisepa.pdfIn PDF document text
    • http://www.pburg94rescue.org/uploads/1/3/0/6/130604349/xakaja-vipadexafoti-visano-rudijoxeje.pdfIn PDF document text
    • http://newhopephotographylakeland.com/uploads/1/3/0/6/130620464/6040895.pdfIn PDF document text
    • http://tidyhangers.co.uk/uploads/1/3/0/6/130620792/09f4065.pdfIn PDF document text
    • http://toyguyomaha.com/uploads/1/3/0/4/130489006/2897245.pdfIn PDF document text
    • http://propertysitters.ca/uploads/1/3/0/5/130589267/luzut-kudenokal-komano-pofuxasa.pdfIn PDF document text
    • http://corvuspress.net/uploads/1/3/0/5/130542728/pakijemofuzu.pdfIn PDF document text
    • http://cpanel.ladse.org/uploads/1/3/0/5/130551264/130551264.html#abductive+deductive+inductiveIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005bc4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5BC4 10472 bytes
SHA-256: 63f9d12e1f1094040f371b9f0bce47febf33aea5ca2c73f44a15e2fb0231d8a9
font_01_sfnt_off0001294a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1294A 2900 bytes
SHA-256: 7e8b98d9136867b767a11127d5c126be13394f73cbe9c36724c9b7ce8701eb69
font_02_sfnt_off0001335c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1335C 17256 bytes
SHA-256: 096072de1a5acb40b3fbd9de10bebc9f60dc28a538dd056171cb0468dc5d5830