Malicious PDF — malware analysis report

Static analysis result for SHA-256 09b4af9faa21bb99…

MALICIOUS

PDF

38.9 KB Authoring application: PDF Studio
MD5: 74e62cc1f9c8174c1ea66d34c10b3feb SHA-1: 94558c07633469ccbaaf6b0de8eae460f041a2fa SHA-256: 09b4af9faa21bb991da194fb144b1aa62a814812da5fc7b348d6e01780e2334c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection and ML classifier also flagged the file as malicious. The embedded URLs likely serve as a distribution mechanism for further malicious content or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dbsarah.com/uploads/1/3/0/6/130640020/dogom-viwifupojus-karusojamu-kinalixiwena.pdf
    • http://metroattorneyreviews.com/uploads/1/3/0/4/130476555/1ca1a49d6365.pdf
    • http://openpaw.net/uploads/1/3/0/6/130604317/31b978877766caa.pdf
    • https://wijibisikenod.weebly.com/uploads/1/3/0/5/130544968/1525dbc69.pdf
    • http://allergy.mediutopia.com/uploads/1/3/0/7/130738527/130738527.html#csu+apply+transfer+guide

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011cc.bin
b430664715c8196a0e4e8b115e64d7398adc85e272616ed273caf144b2250a2d
pdf-font-stream PDF embedded font (sfnt) at offset 0x11CC 8696 bytes