Malicious PDF — malware analysis report

Static analysis result for SHA-256 9abb385df70ef408…

MALICIOUS

PDF

44.2 KB Authoring application: Karbon First seen: 2020-09-07
MD5: 27688d814f60aaa47170e5019a2ba652 SHA-1: 6ead3520b93449c5fe3fe5a28d9e620cee92244c SHA-256: 9abb385df70ef4086552877bde798564d9f75877e13edeaa6b1bd3ead3146e93
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, which is a common technique for distributing malicious content or conducting phishing attacks. The ClamAV detection further supports the malicious nature of the file, classifying it as Pdf.Phishing.TtraffRobotInstall. The presence of a 'download' lure in the document body reinforces the intent to trick users into clicking malicious links. The embedded URLs are the primary IOCs, likely leading to further stages of infection.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://michaelyipfilms.net/uploads/1/3/0/6/130639848/2144737.pdf In PDF document text
    • http://valkrieshopgoddess.com/uploads/1/3/0/5/130552034/zejupubewujowugujom.pdfIn PDF document text
    • http://havanamoments.com/uploads/1/3/0/5/130538939/6e4ca6b22.pdfIn PDF document text
    • http://1600charlestonregionalparkway.com/uploads/1/3/0/5/130544448/tosalebatit.pdfIn PDF document text
    • http://mlachomes.com/uploads/1/3/0/6/130639980/90d3b.pdfIn PDF document text
    • http://skybluecounseling.com/uploads/1/3/0/4/130475982/goluwe.pdfIn PDF document text
    • http://rareronoxe.inity420.com/uploads/2020/01/28/5760893.pdfIn PDF document text
    • http://beesbizz.com/uploads/1/3/0/7/130739180/0ef942.pdfIn PDF document text
    • http://myearthbistro.com/uploads/1/3/0/7/130739674/6b053cffbbcb3.pdfIn PDF document text
    • http://savianflaviusdesigns.com/uploads/1/3/0/3/130379299/diriruvabegu_turamowotuguvo_fawesezonafov.pdfIn PDF document text
    • http://chewoncakes.com/uploads/1/3/0/7/130775528/130775528.html#american+english+file+3+students+book+with+online+skills+-+2nd+edIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013b3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13B3 11408 bytes
SHA-256: 7f12ec259e3079fd3c7e9ec89f0a3a4fe60dbcbab69b1970d2d96f9cd7f05ac2
font_01_sfnt_off00006442.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6442 16648 bytes
SHA-256: 23df611c204fcacea0cb1a1bd4777a81db0301add4d2a86387d9b428d0dd637c