Malicious PDF — malware analysis report

Static analysis result for SHA-256 8fae93e3f8d54661…

MALICIOUS

PDF

59.5 KB Authoring application: QPDF
MD5: b0379cdb3ac5dd90a997a3882fd72fda SHA-1: 377939304795903e67cb6df782fdbed5f27ef173 SHA-256: 8fae93e3f8d546610e93a6d21fb745f23c1855132e7403e5bce60ad7cd502db6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or SEO spam campaigns. The document body contains obfuscated text and URLs, further supporting the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://chapagora.com/uploads/1/3/0/2/130289754/wiwanagorone.pdf
    • http://mhcchurch.org/uploads/1/3/0/2/130270793/luwojenafa.pdf
    • http://myfrancisofassisi.com/uploads/1/3/0/5/130588905/3040796.pdf
    • http://captcush.com/uploads/1/3/0/3/130379529/tigit-dotixo-kubotefufamo.pdf
    • http://drummondislandhotel.com/uploads/1/3/0/4/130483745/1325344.pdf
    • http://www.amiccicanna.store/uploads/1/3/0/8/130873769/tekivudebiputise.pdf
    • http://www.itsallaboutjesus.net/uploads/1/3/0/6/130620987/lanuv_wigujageg_jonuxewam_palapawogajugi.pdf
    • http://baumannfinanzbroker.ch/uploads/1/3/0/5/130551576/a55bbf857.pdf
    • http://sentientmind.org/uploads/1/3/0/6/130639720/8b210.pdf
    • http://solacecycling.com/uploads/1/3/0/5/130550972/vapebemenelu.pdf
    • http://www.franklinlegacyfund.com/uploads/1/3/0/7/130776023/4810038.pdf
    • http://unifiedbuilder.net/uploads/1/3/0/5/130588494/2923770.pdf
    • http://www.joseebuyshouses.com/uploads/1/3/0/6/130639811/ee4b84a418fc27.pdf
    • http://apulumconsllc.com/uploads/1/3/0/6/130605036/benibilotibimalefap.pdf
    • http://thecrookedshrimp.com/uploads/1/3/0/6/130640141/8ff0f985dd768e6.pdf
    • http://elementaldexterity.com/uploads/1/3/0/4/130476317/a696d59417bbe9.pdf
    • http://wukun.com/uploads/1/3/0/6/130639518/subavinid.pdf
    • http://www.thesoftpinkfir.com/uploads/1/3/0/3/130379069/vojasugulojuxise.pdf
    • http://bestlittlelawfirm.com/uploads/1/3/0/8/130813755/linakopelabow.pdf
    • http://siliconvalleyaircharter.com/uploads/1/3/0/6/130639074/zixar.pdf
    • http://bridgepointsearch.com/uploads/1/3/0/6/130639849/gunazatasum.pdf
    • http://swctv.org/uploads/1/3/0/5/130542872/a8680107fe9f.pdf
    • http://epicdb.biz/uploads/1/3/0/9/130969944/8851840.pdf
    • http://webmail.wendywangauthor.com/uploads/1/3/0/6/130605349/lebikal_demaxobopid_fadexumube_lumogujow.pdf
    • http://host168.carmichaelnl.com/uploads/1/3/0/5/130541765/130541765.html#social+media+marketing+strategy+pdf+2019

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011da.bin
6ba2ec365db5b862300510d8d6b13bdc2b3e45fde633265940f3afc3ac7bca37
pdf-font-stream PDF embedded font (sfnt) at offset 0x11DA 8604 bytes
font_01_sfnt_off00008725.bin
0437ae0a8c3b0d4d0bca19117c23f937da5e886acb635ecc2018453b05816554
pdf-font-stream PDF embedded font (sfnt) at offset 0x8725 16168 bytes
font_02_sfnt_off00009ba8.bin
bcba1f59c90ac6eee7b469173b69fe03e4e5e1c9e513b973030807f4bbb724ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x9BA8 1932 bytes