Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd655a0e22b326d8…

MALICIOUS

PDF

44.5 KB Authoring application: Mobipocket Creator
MD5: b0bb4b22c4a73713d0a31d5abb6cd682 SHA-1: c2555d08359c4427611fb995dafd1f4940d1b648 SHA-256: dd655a0e22b326d86071d2ab85f95cc284b0f4fdb44f0250839eeeb665e038e6
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' strongly indicates that the document's content is designed to trick users into believing they are entitled to a prize or funds, requiring them to take further action, such as downloading another PDF. The ClamAV detection further confirms the malicious nature of the file. The embedded URLs likely lead to further stages of the attack, potentially downloading additional malware or redirecting to phishing sites.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laspromos.com/uploads/1/3/0/7/130775374/tutimati.pdf
    • http://generosity.website/uploads/1/3/0/6/130604321/xiwokili_wiligavoruwu_sojuronuti.pdf
    • http://huddin.space/uploads/1/3/0/6/130621905/0bea166b7.pdf
    • http://lighteracu.com/uploads/1/3/0/4/130476462/rosizelute-selobiva-rawiv.pdf
    • http://portagejiu-jitsu.net/uploads/1/3/0/7/130739632/90deb560ee61.pdf
    • http://penninsulatech.com/uploads/1/3/0/2/130289354/8417763.pdf
    • http://seedovation.org/uploads/1/3/0/6/130604368/gifub_roregix_nidulaw_fakiw.pdf
    • http://cakeinaboxco.com/uploads/1/3/0/7/130775396/3446568.pdf
    • http://truexagency.com/uploads/1/3/0/5/130590191/fubogig_vurirovo_rovuv_vadotadifevaj.pdf
    • http://www.homeschoolemanas.com/uploads/1/3/0/6/130620930/6069350.pdf
    • http://keeley-smith.com/uploads/1/3/0/7/130739831/b5f090230b443.pdf
    • http://nataliejimenez.com/uploads/1/3/0/4/130435571/e13ebd8.pdf
    • http://rosselliott.com/uploads/1/3/0/6/130620863/cffb35b72ef6.pdf
    • http://www.natevehealth.com/uploads/1/3/0/6/130621101/dumisesiletafuganab.pdf
    • http://altamayastudios.com/uploads/1/3/0/5/130538841/gotukur.pdf
    • http://bensonderks.com/uploads/1/3/0/2/130288392/guxapokanilekele.pdf
    • http://teakcrafters.com/uploads/1/3/0/7/130775592/zemazukenaf_mipowidinubuv_wabetupedut.pdf
    • http://stakemycoins.com/uploads/1/3/0/5/130542920/857c41f120a776.pdf
    • http://nycraftworks.com/uploads/1/3/0/8/130815437/a1684cd8d9c345b.pdf
    • http://cpanel.newburghmodelrrclub.org/uploads/1/3/0/7/130775997/fefifuditukasi.pdf
    • http://pickmypooltable.com/uploads/1/3/0/3/130379299/kamazobi.pdf
    • http://www.bigheartsfortinybabies.org/uploads/1/3/0/5/130540172/f40b2.pdf
    • http://michaelvickersbaritone.com/uploads/1/3/0/7/130775205/wawidixenabazu.pdf
    • http://mosaicwellington.org/uploads/1/3/0/7/130739525/rusafafof.pdf
    • http://74-123-79-186.mgwnet.com/uploads/1/3/0/6/130620356/784808.pdf
    • http://christykdesign.com/uploads/1/3/0/4/130483238/130483238.html#punjab+state+maa+lakshmi+diwali+pooja+bumper+result+2019

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004874.bin
33764651ca0c150b2826696ec009769cb839addd143a4cb87fe2bfc2c99e9af6
pdf-font-stream PDF embedded font (sfnt) at offset 0x4874 8472 bytes