Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a8425d817d7d931…

MALICIOUS

PDF

44.0 KB Authoring application: Soda PDF
MD5: 37f40988f0c56d603a71ac40801ef7fc SHA-1: 76420429b17cc74d010ab46ea5491e2f1712cf49 SHA-256: 0a8425d817d7d931741cb9a740f41663c79b17778ef62d9d814f4ef45ac41efc
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs, identified as a link farm, suggesting a phishing or redirection attempt. The heuristic 'SE_URGENCY_LURE' indicates the document body likely contains text designed to create a false sense of urgency. While no scripts were directly extracted, the presence of numerous external links points towards a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://theright.buzz/uploads/1/3/0/5/130543305/7996412.pdf
    • http://upfestivals.com/uploads/1/3/0/7/130775830/nawebanigeli-sivesefigan.pdf
    • http://atlanta.diamonds/uploads/1/3/0/5/130539837/malarepado-tokopexega-zalukefavuzowug-panowepaxewib.pdf
    • http://rachaelhudes.com/uploads/1/3/0/2/130270953/790144e.pdf
    • http://tulipsandroses.photography/uploads/1/3/0/5/130588872/60c0b20b5fe469.pdf
    • http://antumbraeducationpartners.com/uploads/1/3/0/2/130292125/zorebelatabizoso.pdf
    • http://puddlescats.com/uploads/1/3/0/4/130483769/xafakotedo_pomamalaluzezu_kojumominojobis_popezono.pdf
    • http://ps163taskforce.org/uploads/1/3/0/2/130272903/7539422.pdf
    • http://diceandwhatever.com/uploads/1/3/0/6/130605390/8695018.pdf
    • http://bryanwalton.com/uploads/1/3/0/7/130739284/7758e211dbf36f.pdf
    • http://consultoriasrojas.com/uploads/1/3/0/2/130288563/c2e342b0f3.pdf
    • http://transformetrica.com/uploads/1/3/0/6/130604803/sisegafus.pdf
    • http://rightjoin.com/uploads/1/3/0/6/130604527/60f9e34b11.pdf
    • http://sxsw360.com/uploads/1/3/0/6/130639747/317f898.pdf
    • http://microweddingsnyc.com/uploads/1/3/0/2/130272364/713e2211.pdf
    • http://digitalmeters.co.uk/uploads/1/3/0/7/130775011/1e148.pdf
    • http://sadeamiarts.com/uploads/1/3/0/4/130436033/4225011.pdf
    • http://asianmassage.net/uploads/1/3/0/2/130291531/butesobikiwapu.pdf
    • http://quotex.fr/uploads/1/3/0/7/130775103/wevujogapafivimowe.pdf
    • http://mmakhaolak.com/uploads/1/3/0/7/130739544/fejaxovatu.pdf
    • http://justjess.me/uploads/1/3/0/2/130270904/sofutuparovipopo.pdf
    • http://nashvillebowling.org/uploads/1/3/0/7/130740368/3798b18541f3.pdf
    • http://soilstewards.com/uploads/1/3/0/7/130775211/2c640d12812b8.pdf
    • http://beckandbloom.com/uploads/1/3/0/2/130272328/fobinifujabosir.pdf
    • http://hawaiieventlighting.com/uploads/1/3/0/5/130538869/3431435.pdf
    • http://dedicated-17.pleasingfood.com/uploads/1/3/0/4/130475966/130475966.html#airasia+mobile+phone+check+in

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004488.bin
75d6a23a7a4263a81d22ee74f8cf6d85d42e5806ae581ac7d9f7d539a929d17e
pdf-font-stream PDF embedded font (sfnt) at offset 0x4488 9144 bytes