Malicious PDF — malware analysis report

Static analysis result for SHA-256 03bee9b7d9574dca…

MALICIOUS

PDF

46.0 KB Authoring application: Adobe PDF Library 9.0
MD5: 63037ab082b515a228b3d880a34b45e6 SHA-1: c2ffac5728feeb7a4038753fce46fad8a097d8ac SHA-256: 03bee9b7d9574dca30528891c149a6758c1b3d1dad9a28cc2ec091100f9f9011
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded URLs, many of which point to PDF files hosted on suspicious domains, indicating a link farm for SEO manipulation or phishing. The document body itself mentions 'Ac market latest version 2019' and includes several of these suspicious URLs, suggesting a lure to download applications or other content. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://werajidinu.agicole-acces.com/uploads/2020/01/29/4061037.pdf
    • http://kunufake.deevki.icu/uploads/2020/01/28/c9237ee621fee.pdf
    • http://mapa.eco-pit.net/uploads/2020/01/29/c7519c.pdf
    • http://noxij.hobbyelectronika.ru/uploads/2020/01/29/wamomevijunujitugut.pdf
    • http://landscapedesign360.com/uploads/1/3/0/6/130605048/kamaxezovotofaw.pdf
    • http://slidemountaincabins.com/uploads/1/3/0/4/130476340/ruwubabilano.pdf
    • https://defediwaxef.weebly.com/uploads/1/3/0/6/130604834/1280257.pdf
    • http://bestjacksonbonding.com/uploads/1/3/0/6/130621758/luvexal.pdf
    • http://silagur.school7u-u.ru/uploads/2020/01/28/8609715.pdf
    • http://xaroz.veramebel.ru/uploads/2020/01/29/surowesasape-jujibo.pdf
    • http://beachesinsrilanka.com/uploads/1/3/0/6/130639841/130639841.html#ac+market++latest+version+2019
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012b2.bin
fe75e8a1e9e23e02bd9c490b821826d12ca99adfd706c0c9960b3283cf8486f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x12B2 9304 bytes
font_01_sfnt_off00005cf5.bin
264da58494b94e4704bc59a91ed7188a2e0b9fc1fa50d69edef70f2621d1673f
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CF5 16080 bytes
font_02_sfnt_off00007132.bin
4d2650191318e8fd439df5003fc9a59485bf31816a31a5f9d83c20b9fc7d82ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x7132 6620 bytes