Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3048773cb24e04a…

MALICIOUS

PDF

37.2 KB Authoring application: Karbon
MD5: bf15ddca50417eb63caf40002156e3f0 SHA-1: 8db28fbd93e169c4234ca9a2d146e00cc7220251 SHA-256: c3048773cb24e04af59c0cdadccf6a4bbd5d4445bc559469778129f8a1e45e06
168 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing with Malicious Attachment T1059.001 PowerShell

The PDF file contains a mass external link farm, with 31 links pointing to other PDF files, many of which are hosted on suspicious domains. The document body text attempts to impersonate an Adobe Reader download, likely to trick users into clicking these malicious links. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic redirection motive. The heuristic 'SE_LOLBIN_RUN_COMMAND' indicates that the document may also contain instructions for executing Windows scripting tools, potentially for further payload delivery or system compromise.

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ruedasdeinnovacion.com/uploads/1/3/0/7/130775254/gefegibufipijiv_kuluguvos_jetijo_bujaxunob.pdf
    • http://nshslibrary.org/uploads/1/3/0/2/130287513/63456605f66.pdf
    • http://sofeatemplate.org/uploads/1/3/0/5/130544584/palavadexupebogisa.pdf
    • http://kirstenboydgoldberg.com/uploads/1/3/0/6/130604690/xevekegosu.pdf
    • http://www.armadamedicalgroup.com/uploads/1/3/0/2/130288458/zovuvites-vadojezazijafon-mabeperinik.pdf
    • http://nips4tips.com/uploads/1/3/0/6/130604018/xalizemirudiv-tiwatedapaj-juzazujur-fevibazupafav.pdf
    • http://adcscripting.online/uploads/1/3/0/7/130776034/4711999.pdf
    • http://fotoprofissional.com/uploads/1/3/0/5/130589345/808544.pdf
    • http://tutorloft.com/uploads/1/3/0/5/130544953/libipuwiwesazuj.pdf
    • http://motticehammond2020.com/uploads/1/3/0/4/130435966/1536766.pdf
    • http://jackyoung.co.za/uploads/1/3/0/6/130620232/bebebafijo.pdf
    • http://wallbrosdrywallservices.com/uploads/1/3/0/2/130273578/zolumak.pdf
    • http://sorsocafe.com/uploads/1/3/0/3/130379146/8233042.pdf
    • http://difficultdriving.com/uploads/1/3/0/6/130621197/tivori-litavo-peron.pdf
    • http://mrebeccaprattfortowncouncil.org/uploads/1/3/0/5/130547576/niposaverik.pdf
    • http://fakation.com/uploads/1/3/0/5/130588927/55ce9106.pdf
    • http://noahco301cportfolio.com/uploads/1/3/0/2/130272362/baf3cd3a26a.pdf
    • http://stjohnslutheranchurchjenison.org/uploads/1/3/0/6/130639215/620666.pdf
    • http://richter-family.rominastiebenphotography.com/uploads/1/3/0/9/130968921/130968921.html#download+adobe+reader+dc+full+offline+installer

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000032b6.bin
02b364fa722a1a08fb5e648dddf4079bbd50ed560477123c0b091383df1ebf9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x32B6 8052 bytes