Malicious PDF — malware analysis report

Static analysis result for SHA-256 87e82e0e662757d2…

MALICIOUS

PDF

103.5 KB Authoring application: OpenOffice.org First seen: 2020-09-24
MD5: ed76d85f3b30a198db521426c5d2a1d9 SHA-1: 4413b036ed40a9b57740df00d2543404ecd48aee SHA-256: 87e82e0e662757d2e994e2f7b9015bf05ed8f7b974f3c67c141b5b5ab7606315
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The heuristic firings reveal it contains a large number of external links, suggesting a link farm designed to redirect users to malicious content. The document body itself contains multiple URLs pointing to PDF files, reinforcing the attack pattern of luring users to download further malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://yambego.com/uploads/1/3/0/5/130590677/85752b88f.pdf In PDF document text
    • http://stsbuildersllc.com/uploads/1/3/0/2/130288416/66b24c74d7.pdfIn macro / runtime command snippet
    • http://danishvillagekringle.com/uploads/1/3/0/2/130287845/rokupil.pdfIn PDF document text
    • http://brookesummers.blog/uploads/1/3/0/6/130605384/butomidove.pdfIn PDF document text
    • http://michellescreations.shop/uploads/1/3/0/5/130551675/8920187.pdfIn PDF document text
    • http://150200martingale.com/uploads/1/3/0/5/130588875/lewuk.pdfIn PDF document text
    • http://zenergieconseil.com/uploads/1/3/0/6/130621575/9668007.pdfIn PDF document text
    • http://ihateqatar.net/uploads/1/3/0/7/130739433/likefunux-muretevu.pdfIn PDF document text
    • http://salaz.photorobots.com/uploads/2020/01/28/tasevinerafasor-leduvetutola-jagamexaxewoven.pdfIn PDF document text
    • http://a1412531xstreamtravel.xsideas.com/uploads/1/3/0/7/130775634/130775634.html#animal+farm+character+quotes+quizletIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001356.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1356 8652 bytes
SHA-256: 4780303c4d032caa0ce283980a2c5e5ac85187b65bf0605b31b471e889492903