Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4e621ae090d791d…

MALICIOUS

PDF

58.2 KB Authoring application: SWFTools
MD5: 93022f02919253d95e4184a884e56798 SHA-1: 9ea19a72d0900695056044dfd851dc103d31b72d SHA-256: b4e621ae090d791dfdf8dc5597e67f4387b2372f77dbb6c1221dbd9373aa8e13
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded URLs pointing to other PDF files hosted on various domains. This technique is often used for SEO poisoning or to distribute malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious distribution intent. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://masonkeim.net/uploads/1/3/0/4/130436096/f69eab.pdf
    • http://andrewmcgeown.com/uploads/1/3/0/7/130739766/673220f37f5ee6.pdf
    • http://www.bigskyalchemy.com/uploads/1/3/0/7/130739498/gupukolun.pdf
    • http://club8inch.com/uploads/1/3/0/6/130604263/2323bb2b7.pdf
    • http://aninhastore.com/uploads/1/3/0/2/130272070/e1bf4e9f.pdf
    • http://nationalcrossday.com/uploads/1/3/0/7/130738845/kuliro.pdf
    • http://i1know.com/uploads/1/3/0/8/130813378/nukudujowiwiza.pdf
    • http://charlesberg.org/uploads/1/3/0/4/130476786/wudixibufalugumu.pdf
    • http://nisfannawaz.com/uploads/1/3/0/6/130604408/nabupikok.pdf
    • http://webdisk.maiawellnessstudio.com/uploads/1/3/0/7/130776521/b0e50.pdf
    • http://cfcgrp.com/uploads/1/3/0/4/130435734/e3b3051c66f00.pdf
    • http://white-poppy.com/uploads/1/3/0/5/130547771/bososumudefofo_sebifufopij_maruzovilawa_xudalufadi.pdf
    • http://consciouslyme.online/uploads/1/3/0/4/130435520/sifurikineworax.pdf
    • http://legacyrealesategroup.com/uploads/1/3/0/6/130604903/2798090.pdf
    • http://michaelsilveyiptec.com/uploads/1/3/0/7/130739618/logemibutug.pdf
    • http://shine-bright-futures.com/uploads/1/3/0/5/130590458/bc12bc21382861.pdf
    • http://hypnotherapymusic.net/uploads/1/3/0/3/130379409/litifijij.pdf
    • http://accesseuropetour.com/uploads/1/3/0/4/130483926/jekezujoreker-sovabero.pdf
    • http://christabot.com/uploads/1/3/0/5/130551072/9532529.pdf
    • http://www.doue.nl/uploads/1/3/0/9/130969011/7f471dbfc696f.pdf
    • http://ashtaashram.com/uploads/1/3/0/6/130604955/tebakozabejirenov.pdf
    • http://thevillagevetpetresort.com/uploads/1/3/0/4/130435597/1344095.pdf
    • http://rocketroys.com/uploads/1/3/0/5/130589429/famajafutaxivakeroli.pdf
    • http://hotelbepop-fi.devsite-1.com/uploads/1/3/0/6/130620750/130620750.html#achyutam+keshavam+krishna+song+mp3+download

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004c84.bin
1cbcc6ccb4c0e39095e587a84d88e28c288fced985aab23597519fc935a1653b
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C84 1428 bytes
font_01_sfnt_off00005674.bin
6ba452c42be1577f8512df5b5835542a545adf7bc0defa5a520e1438160f0947
pdf-font-stream PDF embedded font (sfnt) at offset 0x5674 15556 bytes
font_02_sfnt_off00008232.bin
b25727e634775689474148a893d86f4bf56156600d45851f2b9b988ac3196998
pdf-font-stream PDF embedded font (sfnt) at offset 0x8232 7912 bytes