Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac99606127dd4fbc…

MALICIOUS

PDF

47.5 KB Authoring application: Solid Converter PDF
MD5: 5a971bcdda266737622b8f77855891af SHA-1: 4765fa1a9568a86fae93c9e061301dfc70b49a89 SHA-256: ac99606127dd4fbcc33fb250e1a7b375819b20e46d892bfb12a9cf6311f39166
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files. This is indicative of a link farm used to distribute malicious content or conduct phishing attacks. The ClamAV detection further supports the malicious nature of the file. No scripts were extracted, limiting the ability to determine specific execution methods.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://waeschemode-roesler.net/uploads/1/3/0/5/130590464/tugakuk_kibuwasofum_pefukula.pdf
    • http://lovetilal.thetracker.online/uploads/2020/01/28/83fdd5713c93.pdf
    • http://birgitniefanger.weebly.com/uploads/1/3/0/4/130477193/3786917.pdf
    • http://summeratolg.com/uploads/1/3/0/5/130551621/fejajekejat.pdf
    • https://tokexotedodem.weebly.com/uploads/1/3/0/5/130543740/kakurosa-tilofapezagile.pdf
    • https://zumopojis.weebly.com/uploads/1/3/0/3/130313208/55eb5c86d.pdf
    • http://atlantaareaaeration.com/uploads/1/3/0/4/130488432/5266236.pdf
    • http://thevidvos.com/uploads/2020/01/29/a5c184969242.pdf
    • http://tifimufi.tehnobay.com/uploads/2020/01/28/paguzebupowadatixap.pdf
    • http://mcginnecommconsulting.com/uploads/1/3/0/4/130489072/6721025.pdf
    • http://texanhomestudy.com/uploads/1/3/0/5/130544547/vusubezuvidudide.pdf
    • http://sporttihetki.net/uploads/1/3/0/2/130289532/rebogowus.pdf
    • http://professorstylz.com/uploads/1/3/0/5/130544138/ee0ef88.pdf
    • http://thestrangefantastic.com/uploads/1/3/0/6/130604494/f5e8d5.pdf
    • http://greenlandretail.com/uploads/1/3/0/4/130488847/lukafejiz_gasikufa_revubosiluxew.pdf
    • http://thepinkmews.com/uploads/1/3/0/4/130435902/8669ad25afb8c2.pdf
    • https://gokuzuxoni.weebly.com/uploads/1/3/0/6/130604632/kutev_vogejemaweg.pdf
    • https://vowofaka.weebly.com/uploads/1/3/0/4/130483856/terugogex-fukisazurudiwa-tugowo-duxuxekufevim.pdf
    • http://nikiahseeds.weebly.com/uploads/1/3/0/6/130639347/wudazulomasetexop.pdf
    • http://buko.epiad.com/uploads/2020/01/29/3236626.pdf
    • http://zimi.decenturion.wiki/uploads/2020/01/27/7047826.pdf
    • http://435676578364674396.com/uploads/1/3/0/6/130604218/4165890.pdf
    • https://janegutuzo.weebly.com/uploads/1/3/0/5/130551130/9948536.pdf
    • http://k-fprojects.weebly.com/uploads/1/3/0/5/130589345/suvugipisawij.pdf
    • https://jijirokasosiv.weebly.com/uploads/1/3/0/5/130589384/93cd0fa.pdf
    • http://paseandoablas.weebly.com/uploads/1/3/0/6/130639664/130639664.html#ghodi+bargi+chaal+video+song

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017a0.bin
14eaa8e93ec47a06f5336741f0db2e92b63d8a6b644e398458007271a669d898
pdf-font-stream PDF embedded font (sfnt) at offset 0x17A0 8092 bytes
font_01_sfnt_off000061da.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x61DA 1388 bytes
font_02_sfnt_off00006a3f.bin
79880894e3daf45e571717135af0f5307ca8a6c707e4fc8318ff55098eaf3c5f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A3F 10888 bytes