Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4fa321a01ccad06…

MALICIOUS

PDF

39.1 KB Authoring application: Poppler-utils
MD5: b90e31be1166d100bb53eb6f91d231e2 SHA-1: 3d564876bd78d45c3c68f3c37a4dbd60460cd434 SHA-256: b4fa321a01ccad06490ffb0ab23bdcafcd5df1afb5447ac41abb8e460674b2b4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded external links, a technique commonly used in phishing and SEO spam campaigns to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' and the ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly indicate a phishing or malware distribution intent. The document body, while containing some obfuscated text, also includes these links, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gebusapokamuger.weebly.com/uploads/1/3/0/4/130435988/rotozovajesakago.pdf
    • http://marmot-adventure.com/uploads/1/3/0/2/130288798/lidajofi-mijogurir-zovopoja.pdf
    • https://botavaxemigog.weebly.com/uploads/1/3/0/3/130379361/8e607e19bc.pdf
    • http://vancouvervideopro.com/uploads/1/3/0/6/130622023/8726225.pdf
    • http://nixugapin.rectaparrew.com/uploads/2020/01/28/vulajunof_tilosot_rupodo.pdf
    • http://morahill.com/uploads/1/3/0/5/130546343/sinetitakawemumu.pdf
    • https://zuzeserotuxutur.weebly.com/uploads/1/3/0/5/130588370/divuze-wifusedu-jujig.pdf
    • http://metrophoenixhypnotherapy.com/uploads/1/3/0/6/130605396/9400649.pdf
    • http://triadageless.com/uploads/1/3/0/5/130543006/kavadizapasivi-juvuvob-xusajipuba.pdf
    • http://xujaxarul.sector-arm.ru/uploads/2020/01/28/bf365d855067699.pdf
    • http://10k-running.com/uploads/1/3/0/6/130604651/tesuroxuwujeru_nazabifulofi_solavaji_lasukexapatif.pdf
    • http://babyboot.com.au/uploads/1/3/0/6/130604821/34b58966f71df.pdf
    • http://emilymullikindesign.com/uploads/1/3/0/5/130588461/267f8a5.pdf
    • https://pinejuto.weebly.com/uploads/1/3/0/4/130478261/waruzezozale.pdf
    • http://instagram-support-account.com:80/uploads/2020/01/27/dutipexuterite.pdf
    • http://jowi.befun.xyz/uploads/2020/01/27/33ec9939af6e56.pdf
    • http://allurewaterproofing.com/uploads/1/3/0/2/130271090/xipelekefuvetu_goroguwanovim_gixik_febogune.pdf
    • http://addisonbeaux.com/uploads/1/3/0/2/130291596/c3a4bfb.pdf
    • http://ednpllc.com/uploads/1/3/0/2/130271121/sumubuwixisivebiwux.pdf
    • http://letzdizcuss.com/uploads/1/3/0/5/130551140/76cf50a675c58f.pdf
    • http://labu.bp-bas.com/uploads/2020/01/27/5403374.pdf
    • http://margotmargaux.com/uploads/1/3/0/4/130476270/16289.pdf
    • http://lasixf.com/uploads/2020/01/27/nuzaxofeteni_kekujijava_tesumuj.pdf
    • http://bribrisboutique.com/uploads/1/3/0/3/130323220/a0df22aa180f.pdf
    • http://nhfrea.org/uploads/1/3/0/5/130550911/221bcefde.pdf
    • http://minerhosting.at/uploads/1/3/0/6/130639436/130639436.html#bylaws+template+for+small+business

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017c9.bin
a19b6fc627e4e3c7c04debc3b79199ef58f18147f5d4b6a8778bfaba6c5a2259
pdf-font-stream PDF embedded font (sfnt) at offset 0x17C9 7496 bytes