Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd655a0e22b326d8…

MALICIOUS

PDF

44.5 KB Authoring application: Mobipocket Creator First seen: 2020-09-24
MD5: b0bb4b22c4a73713d0a31d5abb6cd682 SHA-1: c2555d08359c4427611fb995dafd1f4940d1b648 SHA-256: dd655a0e22b326d86071d2ab85f95cc284b0f4fdb44f0250839eeeb665e038e6
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to distribute malicious content. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' strongly indicates that the document's content is designed to trick users into believing they are entitled to a prize or funds, requiring them to take further action, such as downloading another PDF. The ClamAV detection further confirms the malicious nature of the file. The embedded URLs likely lead to further stages of the attack, potentially downloading additional malware or redirecting to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://laspromos.com/uploads/1/3/0/7/130775374/tutimati.pdf In PDF document text
    • http://generosity.website/uploads/1/3/0/6/130604321/xiwokili_wiligavoruwu_sojuronuti.pdfIn PDF document text
    • http://huddin.space/uploads/1/3/0/6/130621905/0bea166b7.pdfIn PDF document text
    • http://lighteracu.com/uploads/1/3/0/4/130476462/rosizelute-selobiva-rawiv.pdfIn PDF document text
    • http://portagejiu-jitsu.net/uploads/1/3/0/7/130739632/90deb560ee61.pdfIn PDF document text
    • http://penninsulatech.com/uploads/1/3/0/2/130289354/8417763.pdfIn PDF document text
    • http://seedovation.org/uploads/1/3/0/6/130604368/gifub_roregix_nidulaw_fakiw.pdfIn PDF document text
    • http://cakeinaboxco.com/uploads/1/3/0/7/130775396/3446568.pdfIn PDF document text
    • http://truexagency.com/uploads/1/3/0/5/130590191/fubogig_vurirovo_rovuv_vadotadifevaj.pdfIn PDF document text
    • http://www.homeschoolemanas.com/uploads/1/3/0/6/130620930/6069350.pdfIn PDF document text
    • http://keeley-smith.com/uploads/1/3/0/7/130739831/b5f090230b443.pdfIn PDF document text
    • http://nataliejimenez.com/uploads/1/3/0/4/130435571/e13ebd8.pdfIn PDF document text
    • http://rosselliott.com/uploads/1/3/0/6/130620863/cffb35b72ef6.pdfIn PDF document text
    • http://www.natevehealth.com/uploads/1/3/0/6/130621101/dumisesiletafuganab.pdfIn PDF document text
    • http://altamayastudios.com/uploads/1/3/0/5/130538841/gotukur.pdfIn PDF document text
    • http://bensonderks.com/uploads/1/3/0/2/130288392/guxapokanilekele.pdfIn PDF document text
    • http://teakcrafters.com/uploads/1/3/0/7/130775592/zemazukenaf_mipowidinubuv_wabetupedut.pdfIn PDF document text
    • http://stakemycoins.com/uploads/1/3/0/5/130542920/857c41f120a776.pdfIn PDF document text
    • http://nycraftworks.com/uploads/1/3/0/8/130815437/a1684cd8d9c345b.pdfIn PDF document text
    • http://cpanel.newburghmodelrrclub.org/uploads/1/3/0/7/130775997/fefifuditukasi.pdfIn PDF document text
    • http://pickmypooltable.com/uploads/1/3/0/3/130379299/kamazobi.pdfIn PDF document text
    • http://www.bigheartsfortinybabies.org/uploads/1/3/0/5/130540172/f40b2.pdfIn PDF document text
    • http://michaelvickersbaritone.com/uploads/1/3/0/7/130775205/wawidixenabazu.pdfIn PDF document text
    • http://mosaicwellington.org/uploads/1/3/0/7/130739525/rusafafof.pdfIn PDF document text
    • http://74-123-79-186.mgwnet.com/uploads/1/3/0/6/130620356/784808.pdfIn PDF document text
    • http://christykdesign.com/uploads/1/3/0/4/130483238/130483238.html#punjab+state+maa+lakshmi+diwali+pooja+bumper+result+2019In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004874.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4874 8472 bytes
SHA-256: 33764651ca0c150b2826696ec009769cb839addd143a4cb87fe2bfc2c99e9af6