Malicious PDF — malware analysis report

Static analysis result for SHA-256 ad158ae40ae18aa7…

MALICIOUS

PDF

50.7 KB Authoring application: pstoedit
MD5: 5ddbe13fd314068bd58837acdb8da092 SHA-1: a5aec552b6e21ebfb576e68ab5cea9bb46621bf1 SHA-256: ad158ae40ae18aa77194984d45b006b9d7e98a228929816d3c3f8ee293800178
128 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF contains embedded JavaScript and a significant number of external links, as indicated by the PDF_JS and PDF_SEO_LINK_FARM heuristics. The ClamAV detection further confirms its malicious nature. The primary function appears to be redirecting users to various external PDF files hosted on numerous domains, likely as part of a phishing or malware distribution campaign. The embedded JavaScript is a common technique for initiating malicious actions within a PDF document.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bellalusso.us/uploads/1/3/0/6/130605161/4786507.pdf
    • http://2ndfloordaga.org/uploads/1/3/0/2/130271245/3a6176899a954.pdf
    • http://kellylcrawford.com/uploads/1/3/0/6/130639356/5726161.pdf
    • https://wowojofiro.weebly.com/uploads/1/3/0/5/130547486/82df68caf72d.pdf
    • http://katanga-online.ru/uploads/2020/01/28/6581092.pdf
    • http://andrianaediting.ca/uploads/1/3/0/6/130620428/695a69f3a.pdf
    • https://vijirenepejix.weebly.com/uploads/1/3/0/5/130589057/bonixalexitatiz.pdf
    • http://msptohumboldtproducts.com/uploads/1/3/0/3/130379083/vipudegafelofemexij.pdf
    • http://dimensionenatura.weebly.com/uploads/1/3/0/3/130313345/fetubuwerafajof_mefizorotuga_xunorar_nilibomoxaj.pdf
    • http://cds-ma.net/uploads/1/3/0/5/130546385/zuwegididepujol_kijobuva.pdf
    • http://uncommoncore.weebly.com/uploads/1/3/0/5/130543148/kaluxegug.pdf
    • http://nelaras.icgauthbanquepoportail.com/uploads/2020/01/28/8384724.pdf
    • https://zawexosuzab.weebly.com/uploads/1/3/0/5/130588583/pobewubugovubepefa.pdf
    • http://kaxaveputu.buygame.xyz/uploads/2020/01/27/zedevajo.pdf
    • http://zofam.wondersaw.ru/uploads/2020/01/27/4885662.pdf
    • http://sojigib.dkto.pro/uploads/2020/01/29/lazifumis.pdf
    • http://adobeforfashion.net/uploads/1/3/0/6/130621098/dekovejiw.pdf
    • http://clinicalresearchorganization.ru/uploads/2020/01/28/b4ce777b5fb.pdf
    • http://tifowewav.torepair.ru/uploads/2020/01/28/c851f9decd8b.pdf
    • http://jixeru.panda-opt.ru/uploads/2020/01/27/masuvifegiz.pdf
    • http://tsarevitsa.ru/uploads/2020/01/28/doxabeg.pdf
    • http://wevaz.saylove.info/uploads/2020/01/29/74257e88.pdf
    • http://whatthefunkdenver.com/uploads/1/3/0/5/130551338/4810036.pdf
    • http://thehappygirlstore.com/uploads/1/3/0/2/130270905/130270905.html#resume+template+word+with+picture

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001110.bin
1c9854bdc1649f1836287e4f2711f4fbe3211b2f5af33c1d1f90a29c7ef996fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x1110 8372 bytes