Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a50e14184d080c1…

MALICIOUS

PDF

44.4 KB Authoring application: Inkscape
MD5: b06c73b5622db437cdcac66203fc2de7 SHA-1: 3c74d90114fde9f01b6c232eca1c6793e950a22e SHA-256: 0a50e14184d080c1eaf243cd01524d833de0915ff39780fa08437104e7e9a34b
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO spam or to distribute malicious content. ClamAV detected this file as Pdf.Phishing.TtraffRobotInstall, and an ML classifier also flagged it as malicious. The embedded URLs are the primary IOCs, suggesting a campaign focused on link farming or redirecting users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mgracetransitions.com/uploads/1/3/0/6/130639563/c5909b0e453a4d3.pdf
    • http://mta-sts.mail.zoesgraphics.com/uploads/1/3/0/2/130272372/168244fa.pdf
    • http://musclegearasia.net/uploads/1/3/0/2/130289171/0909bdda2.pdf
    • http://mikepaganrealtor.com/uploads/1/3/0/7/130738988/valobadobukema.pdf
    • http://northhaledontreeexperts.com/uploads/1/3/0/2/130289436/sovufuvibogelonas.pdf
    • http://acadiaextracts.com/uploads/1/3/0/8/130813779/galuwipagusiw-wajoremagomaw-tunawenomovodi-remixaxa.pdf
    • http://lwkdesigns.com/uploads/1/3/0/6/130604322/1669043.pdf
    • http://zeustreeservice.net/uploads/1/3/0/6/130604222/2afe20.pdf
    • http://dian.banjodanielmusic.com/uploads/1/3/0/5/130545581/baranuzes.pdf
    • http://mta-sts.xinchengqiu.com/uploads/1/3/0/8/130873732/08a4ddca5f94.pdf
    • http://people.co.nz/uploads/1/3/0/6/130639990/mafen.pdf
    • http://morrowworldradio.com/uploads/1/3/0/5/130551191/4131492.pdf
    • http://hotelero.online/uploads/1/3/0/4/130435743/vibemexasugevugapir.pdf
    • http://www.chequeredflagauto.com/uploads/1/3/0/7/130738666/guwuno-wapilebototon-webaladuwalonaw.pdf
    • http://oslorelocationservices.net/uploads/1/3/0/8/130813362/8581615.pdf
    • http://kolossus.com/uploads/1/3/0/4/130490776/809c7045df1d.pdf
    • http://liveloveindigo.com/uploads/1/3/0/8/130873841/113babadb8206.pdf
    • http://waggingtailsnwetnoses.net/uploads/1/3/0/3/130323322/d556a66d7d4.pdf
    • http://qualloworldonelovetravel.voyagerwebsites.com/uploads/1/3/0/6/130621588/130621588.html#faraday%27s+second+law+of+electrolysis+equation
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002d81.bin
0fff8637fe4384a78c319bbc38c9924ea46f85d2542dee181d8687891991a99e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D81 2944 bytes
font_01_sfnt_off00003751.bin
f2bc6a67d4be5afe4af4f244e76e8e2e605e02b13ab9833961e222a90737731f
pdf-font-stream PDF embedded font (sfnt) at offset 0x3751 16196 bytes
font_02_sfnt_off00004f54.bin
38def73f23c7a30ba04c90a2d0cc6380b9f1304d0f3404f4cb08335786ea4345
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F54 7908 bytes