Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3048773cb24e04a…

MALICIOUS

PDF

37.2 KB Authoring application: Karbon First seen: 2020-09-07
MD5: bf15ddca50417eb63caf40002156e3f0 SHA-1: 8db28fbd93e169c4234ca9a2d146e00cc7220251 SHA-256: c3048773cb24e04af59c0cdadccf6a4bbd5d4445bc559469778129f8a1e45e06
200 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing with Malicious Attachment T1059.001 PowerShell

The PDF file contains a mass external link farm, with 31 links pointing to other PDF files, many of which are hosted on suspicious domains. The document body text attempts to impersonate an Adobe Reader download, likely to trick users into clicking these malicious links. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic redirection motive. The heuristic 'SE_LOLBIN_RUN_COMMAND' indicates that the document may also contain instructions for executing Windows scripting tools, potentially for further payload delivery or system compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ruedasdeinnovacion.com/uploads/1/3/0/7/130775254/gefegibufipijiv_kuluguvos_jetijo_bujaxunob.pdf In PDF document text
    • http://nshslibrary.org/uploads/1/3/0/2/130287513/63456605f66.pdfIn PDF document text
    • http://sofeatemplate.org/uploads/1/3/0/5/130544584/palavadexupebogisa.pdfIn PDF document text
    • http://kirstenboydgoldberg.com/uploads/1/3/0/6/130604690/xevekegosu.pdfIn PDF document text
    • http://www.armadamedicalgroup.com/uploads/1/3/0/2/130288458/zovuvites-vadojezazijafon-mabeperinik.pdfIn PDF document text
    • http://nips4tips.com/uploads/1/3/0/6/130604018/xalizemirudiv-tiwatedapaj-juzazujur-fevibazupafav.pdfIn PDF document text
    • http://adcscripting.online/uploads/1/3/0/7/130776034/4711999.pdfIn PDF document text
    • http://fotoprofissional.com/uploads/1/3/0/5/130589345/808544.pdfIn PDF document text
    • http://tutorloft.com/uploads/1/3/0/5/130544953/libipuwiwesazuj.pdfIn macro / runtime command snippet
    • http://motticehammond2020.com/uploads/1/3/0/4/130435966/1536766.pdfIn PDF document text
    • http://jackyoung.co.za/uploads/1/3/0/6/130620232/bebebafijo.pdfIn PDF document text
    • http://wallbrosdrywallservices.com/uploads/1/3/0/2/130273578/zolumak.pdfIn PDF document text
    • http://sorsocafe.com/uploads/1/3/0/3/130379146/8233042.pdfIn PDF document text
    • http://difficultdriving.com/uploads/1/3/0/6/130621197/tivori-litavo-peron.pdfIn PDF document text
    • http://mrebeccaprattfortowncouncil.org/uploads/1/3/0/5/130547576/niposaverik.pdfIn PDF document text
    • http://fakation.com/uploads/1/3/0/5/130588927/55ce9106.pdfIn PDF document text
    • http://noahco301cportfolio.com/uploads/1/3/0/2/130272362/baf3cd3a26a.pdfIn PDF document text
    • http://stjohnslutheranchurchjenison.org/uploads/1/3/0/6/130639215/620666.pdfIn PDF document text
    • http://richter-family.rominastiebenphotography.com/uploads/1/3/0/9/130968921/130968921.html#download+adobe+reader+dc+full+offline+installerIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000032b6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x32B6 8052 bytes
SHA-256: 02b364fa722a1a08fb5e648dddf4079bbd50ed560477123c0b091383df1ebf9b