Malicious PDF — malware analysis report

Static analysis result for SHA-256 f46513d1e74b19dc…

MALICIOUS

PDF

107.9 KB Authoring application: LibreOffice First seen: 2020-09-24
MD5: f01304a5d162c2c34716e28cd8c70b0e SHA-1: c6634c91bb08d04d6b3ff9dba8894e7a07112e75 SHA-256: f46513d1e74b19dc1e8b2ee9c7929c06d6f5b9b6ecdebec0c248bb321703347c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on various domains. This is indicative of a link farm or phishing lure, designed to direct users to potentially malicious content. The ClamAV detection and ML classifier further support its malicious nature. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nantcaw.co.uk/uploads/1/3/0/6/130604493/tisoximinuboge_sugagafow.pdf In PDF document text
    • http://rezoj.bassporshop.com/uploads/2020/01/28/vojevoxosekedusupave.pdfIn PDF document text
    • http://bmday.ru/uploads/2020/01/28/muzasixezaralugil.pdfIn PDF document text
    • http://xeza.audiostart28.icu/uploads/2020/01/28/vogibawufuvogami.pdfIn PDF document text
    • http://3dmarinerswalk.com/uploads/1/3/0/6/130639489/fibakir-zurumasifodisiz.pdfIn PDF document text
    • http://amudyomi.net/uploads/1/3/0/6/130621979/mozowazez.pdfIn PDF document text
    • http://allstardogs.training/uploads/1/3/0/6/130605292/dewadumoxama.pdfIn PDF document text
    • http://vuwuxipi.lakan.ru/uploads/2020/01/28/fe7f9dd.pdfIn PDF document text
    • http://newlifefitz.org/uploads/1/3/0/4/130478110/9248084.pdfIn PDF document text
    • http://countryseasonsbnb.com/uploads/1/3/0/6/130603852/7757430.pdfIn PDF document text
    • http://newyorkalternativecare.com/uploads/1/3/0/4/130435833/wuvizudopekulasexe.pdfIn PDF document text
    • http://bluffcitycreative.com/uploads/1/3/0/4/130435721/kogabasipus.pdfIn PDF document text
    • http://miracleinabucket.com/uploads/1/3/0/6/130621569/130621569.html#marathi+chavat+kathaIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013e6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13E6 6896 bytes
SHA-256: 272a68af74d5bb5423cef65f3e883bfb4b57c6c55ee93b7268866148e530bf1f
font_01_sfnt_off00011c18.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11C18 1400 bytes
SHA-256: 44e2fd5091b7002d7aec4ca5ffadea11308e4ae8e0e05aae0b342eeecf8425d3
font_02_sfnt_off00012312.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12312 16028 bytes
SHA-256: ca889182d22413b1a5b6446cd5d954c095bfc2c8b2fec1022b19199100617195
font_03_sfnt_off00013bf0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13BF0 23648 bytes
SHA-256: 41e1f81db717cc7ef8ced1d46e6cba29e99204b095e22190e98817cba384e525