Malicious PDF — malware analysis report

Static analysis result for SHA-256 87658012f943e94f…

MALICIOUS

PDF

41.9 KB Authoring application: Nitro PDF
MD5: 4b9629adba46414cbbe0079a047d8f06 SHA-1: 1b14f6e3067547153055ae407a30c4a0534438dc SHA-256: 87658012f943e94fbc59ec0c0ca83ca1115705b6485a374fff8640282f5292ba
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or redirection to malicious content. The SE_LOLBIN_RUN_COMMAND heuristic indicates the presence of instructions that could execute system commands, likely to download and execute further payloads. The ClamAV detection further confirms its malicious nature, classifying it as Pdf.Phishing.TtraffRobotInstall.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lgj.de/uploads/1/3/0/3/130313177/firakinik-lejarimida.pdf
    • http://bucharestinthebeltway.com/uploads/1/3/0/3/130323092/bipujunu-tiwaw.pdf
    • http://4frontresidency.com/uploads/1/3/0/2/130289632/godabub.pdf
    • http://scipromath.net/uploads/1/3/0/6/130639181/1391242.pdf
    • http://hostmaster.londonimagingnetwork.com/uploads/1/3/0/8/130873954/pigudufejalizabexof.pdf
    • http://perstaxllc.com/uploads/1/3/0/7/130740178/23e0eb6.pdf
    • http://fsq.me/uploads/1/3/0/6/130639856/gedakewijawivuv.pdf
    • http://belkran-bk.com/uploads/1/3/0/6/130639807/a6bf97b81.pdf
    • http://americalibertyforum.com/uploads/1/3/0/5/130589400/be9df8e73.pdf
    • http://qijidaoyin.net/uploads/1/3/0/7/130776307/aeb3e3.pdf
    • http://jordanqualls.info/uploads/1/3/0/6/130621614/5088557.pdf
    • http://bookerteesmore.com/uploads/1/3/0/7/130776756/375383ac83840.pdf
    • http://scandinavian-relocationgroup.com/uploads/1/3/0/2/130291783/padowubabuwo.pdf
    • http://globalstrangers.com/uploads/1/3/0/4/130483191/jituxan_dulejudufajur.pdf
    • http://mormon-clothes.com/uploads/1/3/0/6/130639629/e398fbec309710.pdf
    • http://auditionhell.com/uploads/1/3/0/6/130604758/7089534.pdf
    • http://copeid.com/uploads/1/3/0/6/130639652/3344967.pdf
    • http://austincrouch.info/uploads/1/3/0/6/130620955/wubelofifofil.pdf
    • http://scandinavian-relocation.com/uploads/1/3/0/5/130551103/766d3.pdf
    • http://biggestbenefit.com/uploads/1/3/0/7/130776077/7286276.pdf
    • http://broketheinterweb.com/uploads/1/3/0/5/130588674/wuwobanek.pdf
    • http://loveisthewayhome.com/uploads/1/3/0/4/130483515/simimoxuvaxove-xatetom-rurolulosinojon.pdf
    • http://carolegelkerartist.info/uploads/1/3/0/3/130324206/62feb0a3a184.pdf
    • http://christani.info/uploads/1/3/0/2/130274146/bizozikoxuxiwur.pdf
    • http://xtwdn6.brdge.org/uploads/1/3/0/9/130968997/130968997.html#aviation+english+vocabulary
    • http://4frontresidency.com/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000428a.bin
5481b842dfc510b8c52b1a59249d1bc271f2cacda66eeb21051383c3cabe96c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x428A 7364 bytes