Malicious PDF — malware analysis report

Static analysis result for SHA-256 e66590998f8c7442…

MALICIOUS

PDF

38.3 KB Authoring application: Solid Converter PDF First seen: 2021-04-10
MD5: 676c8fdb989749d47b75a80d83005318 SHA-1: fb412bbcc6e9c9f8eb9c1fc90c6ca37544e3e1a6 SHA-256: e66590998f8c7442d067afd71afd70ed7b07264dad8df8a4882bd7f4561b20df
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://niagaranaturalfertility.ca/uploads/1/3/0/3/130323311/6096996.pdf In PDF document text
    • https://gasejivezanolow.weebly.com/uploads/1/3/0/2/130288559/vovuki-nexiwatirasufaj-xanovamuda.pdfIn PDF document text
    • http://lax.safeautokzn.ru/uploads/2020/01/27/305495.pdfIn PDF document text
    • http://lachen.weebly.com/uploads/1/3/0/2/130287945/tobowulezepew-selali-muzose-zarimorosem.pdfIn PDF document text
    • http://novostroy-krd.ru/uploads/2020/01/27/0180b638ce1.pdfIn PDF document text
    • http://mrbrushgrade5.ca/uploads/1/3/0/5/130543099/fezivovor-feriwofifefot-didipekivuf.pdfIn PDF document text
    • http://buyhempoilnow.shop/uploads/1/3/0/3/130313605/8288567.pdfIn PDF document text
    • http://gugafum.flashapp.online/uploads/2020/01/28/2c1d38.pdfIn PDF document text
    • http://drewwatsonpups.com/uploads/1/3/0/3/130313091/130313091.html#esl+conversation+question+cards+pdfIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013d6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13D6 8528 bytes
SHA-256: 22b67505b2fa3ebe42c75b646a066401e344d8fdabb7d8b016c925071f41ce33