Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8a7f8f86cfac19f…

MALICIOUS

PDF

48.8 KB Authoring application: Pdftk
MD5: 1c725f25be15ef8aadde96c70f836ccc SHA-1: 200030b61421c251b47ac909b0b4f621dda7b980 SHA-256: b8a7f8f86cfac19fe2a51c1d584e718c0aa47e50c8dc5d70020d8940ca829284
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which are dynamically generated and point to other PDF files. The document body text, while appearing to be about creating editable PDFs, contains embedded URLs that redirect to these malicious PDF files. This indicates a phishing or redirection campaign designed to lead users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://smoothtransitionservices.com/uploads/1/3/0/5/130551720/parunawukef-daxagepepigudok-newiwupoka-pasul.pdf
    • http://dodgeballaustralia.com/uploads/1/3/0/5/130588731/dee71d5.pdf
    • http://annalisadoebley.com/uploads/1/3/0/5/130540104/7142113.pdf
    • http://nylarose.co/uploads/1/3/0/7/130738994/4935139.pdf
    • http://publicationorganizer.com/uploads/1/3/0/5/130545480/vitirobagevobomugik.pdf
    • http://radjam.org/uploads/1/3/0/5/130589010/midiju_luwutesuvenawix_rezejaruji.pdf
    • http://mentalpraxis.net/uploads/1/3/0/7/130739480/kufedeb-lisatovi-liforu.pdf
    • http://belongtoglasgow.co.uk/uploads/1/3/0/4/130489144/zepuxesidufu.pdf
    • http://assembleiadedeusministerioalfa.com/uploads/1/3/0/7/130739885/zufeb.pdf
    • http://www.thegoldenknot.com/uploads/1/3/0/6/130639444/butowekidigeru_mekovezomafi_fobuzamusip_xatavata.pdf
    • http://hessenergyllc.com/uploads/1/3/0/6/130604105/xiziwobomilagi-gomuw-bumugujuzuwodu.pdf
    • http://cleanforetagsstad.com/uploads/1/3/0/7/130739697/wawov.pdf
    • http://pancanadaimmigration.ca/uploads/1/3/0/6/130639521/gitagifinixafuz.pdf
    • http://agapeeducationalconsultantsandtrainers.org/uploads/1/3/0/5/130547150/dixibatevam-mosag.pdf
    • http://probalancemassage.com/uploads/1/3/0/6/130620752/8fb679bf84fc70c.pdf
    • http://emmajeanclothing.com/uploads/1/3/0/2/130291585/7616623.pdf
    • http://mx.jlsmither.com/uploads/1/3/0/7/130739098/zojinobizizopuga.pdf
    • http://www.thebarnatcollinscrest.com/uploads/1/3/0/3/130379821/a5b8f6caaa1e99.pdf
    • http://miandhepiano.com/uploads/1/3/0/2/130274267/robuwagugiwegu.pdf
    • http://aestheticsplus.co/uploads/1/3/0/6/130603997/9641066.pdf
    • http://hostmaster.roxelpta.org/uploads/1/3/0/6/130639160/9345277.pdf
    • http://moonstory.click/uploads/1/3/0/8/130814066/jetedoj_kenemapukidi_lanetigefipitow.pdf
    • http://zionluthwaterloo.com/uploads/1/3/0/2/130274166/xuzibuniniga.pdf
    • http://proper-boston.com/uploads/1/3/0/5/130588225/nuzurej_tudapolowu.pdf
    • http://archie-rodriguez.pleasingfood.com/uploads/1/3/0/7/130776118/130776118.html#how+to+make+an+editable+pdf+in+acrobat+pro+dc

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f78.bin
254991bd3c0320c5cc478c064b41763894aac161393ad6721b8261fab573cc79
pdf-font-stream PDF embedded font (sfnt) at offset 0xF78 7532 bytes