Malicious PDF — malware analysis report

Static analysis result for SHA-256 f401d1fcc6ffdc01…

MALICIOUS

PDF

40.1 KB Authoring application: pstoedit
MD5: c4951cff08a797bba53f4ca3c2d5e0af SHA-1: 3db1411186154135dff33b9e2e01b3842dc1e664 SHA-256: f401d1fcc6ffdc01a96ba44a885e9a8bbba090f52f2df79272ac97e9f700ca47
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded external links, a technique often used for SEO spam or to redirect users to phishing or malware download sites. The ClamAV detection and ML classifier strongly indicate malicious intent. The heuristic PDF_SEO_LINK_FARM specifically identifies this pattern, with the first URL being http://nannytram.com/uploads/1/3/0/6/130639462/tuzizebus_sigepenoz.pdf. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nannytram.com/uploads/1/3/0/6/130639462/tuzizebus_sigepenoz.pdf
    • http://mountainplayschool.com/uploads/1/3/0/5/130540280/safegunoresarita.pdf
    • http://zimokajeke.planbani.ru/uploads/2020/01/29/tixuzenuba.pdf
    • http://divinewillschool.com/uploads/1/3/0/6/130620681/7201054.pdf
    • http://noordinarygames.com/uploads/1/3/0/6/130620522/jiwivudopirananubego.pdf
    • http://carousellearning.com/uploads/1/3/0/4/130488172/f31731c9a.pdf
    • http://polozoffdesign.com/uploads/1/3/0/5/130588545/ritofumogajet-lobupotur-gisox-sugimas.pdf
    • http://acceleratecleaning.com/uploads/1/3/0/6/130605280/bofevozer-towebaxetezi.pdf
    • http://businessloanbrokercoaching.com/uploads/1/3/0/2/130289523/d612b4964d.pdf
    • http://emilyranney.com/uploads/1/3/0/4/130489054/f63348.pdf
    • http://mstvirginhair.com/uploads/1/3/0/4/130477755/5263909.pdf
    • http://printyoursport.co.uk/uploads/1/3/0/2/130270997/xenapi_wozeruregi.pdf
    • http://woodlandstuition.com/uploads/1/3/0/6/130639636/130639636.html#arecaceae+palm+family

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000147c.bin
0654fba52da8dde517edb413f97790b7604aa2e9c1a790d8d2934cd0017c108d
pdf-font-stream PDF embedded font (sfnt) at offset 0x147C 7600 bytes