Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd16ca19762532c6…

MALICIOUS

PDF

42.6 KB Authoring application: pstoedit
MD5: d3f12b68cafe0e80a08474c0f842a982 SHA-1: aa74ea669c995cc99c03ee74d927a4be150d38e0 SHA-256: dd16ca19762532c626fd9640132ba1cd11daab8c8b58d03c3f273b1e54fd7314
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified as a link farm, with the primary purpose of directing users to download other PDF files. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent. The embedded URLs are likely part of a phishing or malware distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fonemalami.xpinoza.com/uploads/2020/01/28/d7caaa5e.pdf
    • http://marketdata-group.com/uploads/1/3/0/6/130639465/xalagize.pdf
    • http://s6wraps.com/uploads/1/3/0/3/130379121/f1236272bb235.pdf
    • http://applesandbooks.com/uploads/1/3/0/6/130605443/4252371.pdf
    • http://schanwriter.com/uploads/1/3/0/6/130604675/2f8462616f120.pdf
    • http://ccmclb.com/uploads/1/3/0/3/130379160/7313818.pdf
    • http://ruguwuwun.ponoxy.store/uploads/2020/01/28/dikitabupifag.pdf
    • http://k2zmedia.com/uploads/1/3/0/2/130289692/nizedo-jifeturotuwo-kajomazesojod.pdf
    • http://statewidefacilitiesservices.com/uploads/1/3/0/5/130589243/silimabexifu.pdf
    • https://jawonujelile.weebly.com/uploads/1/3/0/4/130483551/besoduwo-zarow-seruzunes-wurukoduwokuja.pdf
    • http://plania.it/uploads/1/3/0/4/130483412/varigufisuf_deboke.pdf
    • http://angelssandlot.com/uploads/1/3/0/4/130476984/130476984.html#flashpoint+paradox+latino+descargar

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000132d.bin
6fe422ec2bb15f98c9893bc54ab8c3a6836db7dcfa5cf7662cc073681d869199
pdf-font-stream PDF embedded font (sfnt) at offset 0x132D 8640 bytes
font_01_sfnt_off00005a9f.bin
92370270cdbe39f3eae1a26dbb538d86b5746f3496c339c942566f1ec0a0204a
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A9F 17648 bytes