Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd56bd288523ca7d…

MALICIOUS

PDF

37.4 KB Authoring application: LibreOffice
MD5: f7221bc7dd42d166d8a52753bd2ff11e SHA-1: 32deba296e72eb8a4e7f95d8f018461e551a4458 SHA-256: cd56bd288523ca7d7611c0be1e0a58af1736e0dc56ffa7ad6d617a4a5a5d04a3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique commonly used for SEO link farms and potentially for distributing malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent. The document body is heavily corrupted and unreadable, but the heuristic firings and numerous suspicious URLs are sufficient to assess the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thefurniturefolks.com/uploads/1/3/0/5/130589360/7775026.pdf
    • http://interview-tools.net/uploads/1/3/0/7/130775199/9179131.pdf
    • http://alderearlycollege.org/uploads/1/3/0/5/130590717/39fe1.pdf
    • http://insideosuokc.net/uploads/1/3/0/5/130588685/d373d749c.pdf
    • http://lockedsecurestorage.com/uploads/1/3/0/2/130270905/1130164.pdf
    • http://renabatt.org/uploads/1/3/0/4/130435509/0ad71d38a3efe87.pdf
    • http://retrogameshownight.com/uploads/1/3/0/4/130483769/8be6fb96.pdf
    • http://mailbear.org/uploads/1/3/0/8/130874437/21f7761eafb0eb.pdf
    • http://mobilizerrs.com/uploads/1/3/0/7/130775644/510846e657.pdf
    • http://igetweddings.com/uploads/1/3/0/5/130538956/1967514.pdf
    • http://learninator.net/uploads/1/3/0/7/130776886/lukaforimegipev_dagiwubewiwijo.pdf
    • http://kenplattlaw.net/uploads/1/3/0/5/130550973/monukakozegiwi.pdf
    • http://powergeardrums.com/uploads/1/3/0/6/130621143/dc40735d39.pdf
    • http://band-ems.org/uploads/1/3/0/4/130489572/fc750.pdf
    • http://www.wupbl.com/uploads/1/3/0/5/130539046/9008796c45109.pdf
    • http://store.fennellyfarms.com/uploads/1/3/0/6/130640048/44fe04e1897.pdf
    • http://mirasolrehab.net/uploads/1/3/0/5/130538923/wunalimawarozaxifoje.pdf
    • http://host142.carmichaelnl.com/uploads/1/3/0/4/130435532/130435532.html#distillation+column+energy+balance

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000035da.bin
0f4dcb3cf27d1289eee91f94ea13a6259d3ef6b5d5bd662f33a1c464e5d84d7b
pdf-font-stream PDF embedded font (sfnt) at offset 0x35DA 7928 bytes