Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2ee60386db3eab1…

MALICIOUS

PDF

55.9 KB Authoring application: Soda PDF
MD5: 272d5cfcc3a98a65d40962c4aaebe940 SHA-1: 7e0eeb55c51f7d20b58ac07f45d543c1c876dcb7 SHA-256: d2ee60386db3eab1fdd87ccd30d3c4a3f44645d5b9752e039b69a3b98011a74f
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, directing users to various domains. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier's high confidence score further indicate malicious intent. The primary goal appears to be redirecting users to potentially malicious content hosted on these external domains, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bukomug.storeclick.xyz/uploads/2020/01/27/bc91f82b9987.pdf
    • http://rostelekomlk.xyz/uploads/2020/01/27/ronatunimawufo.pdf
    • http://agenkastam.com/uploads/1/3/0/4/130476589/8724635.pdf
    • http://advantageprotocol.com/uploads/1/3/0/5/130539846/3842012.pdf
    • http://lumidixo.baccy-earwing.info/uploads/2020/01/28/memilipize.pdf
    • http://miv.olegdfr.fr/uploads/2020/01/28/welaxena-zudiru.pdf
    • http://fefapuw.pansionat-chaika.com/uploads/2020/01/28/sebedo-silojifogugeb.pdf
    • http://gypsyscentsandfiber.com/uploads/1/3/0/5/130551179/b54cb1f4.pdf
    • http://michalpaczkowski.com/uploads/1/3/0/5/130551140/libefu-doruranotol-kowezumosit.pdf
    • http://bewagav.bearofrosess.ru/uploads/2020/01/28/8545855.pdf
    • http://mooncliptool.com/uploads/1/3/0/5/130551064/6a2ba7398.pdf
    • https://xegawokanitej.weebly.com/uploads/1/3/0/5/130551237/6219977.pdf
    • http://lanamilu.dcdinspecciones.com/uploads/2020/01/29/2824728.pdf
    • http://cafedonruiz.com/uploads/1/3/0/6/130639329/vagawixiradodituzuj.pdf
    • http://konilasu.suddenweblink.online/uploads/2020/01/27/8856315.pdf
    • http://ribozuniro.galadariassociates.com/uploads/2020/01/27/sewiba_juxoniri.pdf
    • http://jadin.vipiski-besplatno11.icu/uploads/2020/01/28/pelizafatu.pdf
    • http://stayinghome.nl/uploads/1/3/0/4/130493714/zumazaruwavefe-panageta-parezituvus-lanavubeke.pdf
    • http://mtymielikki.fi/uploads/1/3/0/5/130588511/2cf5f1f3754e2ab.pdf
    • http://rjgwoodworking.com/uploads/1/3/0/6/130604815/3e1e5d43.pdf
    • http://ketchikanwhales.com/uploads/1/3/0/4/130489706/f28ca2.pdf
    • http://quietpoppy.com/uploads/1/3/0/2/130271004/cc01b925164208.pdf
    • http://normandyoptical.biz/uploads/1/3/0/2/130288577/9ee81812767.pdf
    • https://jufofelafoguge.weebly.com/uploads/1/3/0/5/130588419/04567af62.pdf
    • http://theexpertdoc.com/uploads/1/3/0/6/130604256/2046484.pdf
    • http://bodyworkbybarb.com/uploads/1/3/0/2/130289686/130289686.html#onani+master+kurosawa+my+hero+academia
    • https://xegawokanitej.wee

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00007c30.bin
b132824022435b7ad42e34e79dc3fef301e2123482cc2d3bf20848101d6c1daa
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7C30 19684 bytes
font_00_sfnt_off000017f6.bin
7d74aab702bb48a7f0c4f7f2916ff2b6000d0fcff3629c3a00503be6cdf19b44
pdf-font-stream PDF embedded font (sfnt) at offset 0x17F6 8728 bytes
font_02_sfnt_off00009a54.bin
bae3d4931d9fe8ae3f6371ff23f2da5e89ff4f2ba47fd6bdd912ba7f27c180c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x9A54 4444 bytes