Malicious PDF — malware analysis report

Static analysis result for SHA-256 0dff47b4acbbb118…

MALICIOUS

PDF

34.7 KB Authoring application: Mobipocket Creator
MD5: fc07154f3a33740e85b4f80023f932f8 SHA-1: 0ebd5facfe9a628b529dd3b6307d2d4f9558fca9 SHA-256: 0dff47b4acbbb118fb4e995221ced4d37ac767daafcd160d33218ca996fd6c7b
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file exhibits characteristics of a link farm or SEO spam, with a high number of embedded URLs pointing to other PDF files hosted on various domains. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to distribute malware or engage in phishing by directing users to potentially harmful content. The document body contains garbled text and what appears to be code snippets, but no clear instructions or lures are discernible from the readable portions.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wildflowerfilm.com/uploads/1/3/0/2/130289496/xefagunije_tisojolukod_xozazedederum.pdf
    • http://whiskeyandwine.net/uploads/1/3/0/6/130605405/054a51fd714.pdf
    • http://moir.se/uploads/1/3/0/3/130313610/87ee5d26.pdf
    • http://mrfixitchicagoland.com/uploads/1/3/0/8/130813063/wodebimab-peruvo-jupovozetuku-waboju.pdf
    • http://mpautosales.co/uploads/1/3/0/8/130874377/lexusunofubagixotiko.pdf
    • http://rootsphillyyoga.com/uploads/1/3/0/4/130476083/a435d291bb1a910.pdf
    • http://www.anamcara.co.nz/uploads/1/3/0/6/130639356/17f0e.pdf
    • http://www.paulcoxon.co.uk/uploads/1/3/0/5/130589222/xamirofopigat.pdf
    • http://bartbenson.com/uploads/1/3/0/3/130313274/soveberuri.pdf
    • http://365roadsideassist.com.au/uploads/1/3/0/5/130551179/6fd33a6b.pdf
    • http://optimumservicioslegales.com/uploads/1/3/0/5/130542912/pabawefa-tuwasoruken.pdf
    • http://mohakshroff.net/uploads/1/3/0/2/130272619/f3e69fccf8009d.pdf
    • http://mworchestra.com/uploads/1/3/0/7/130775672/9156043.pdf
    • http://click4cushions.co.uk/uploads/1/3/0/7/130738526/gezemubuvid-raxadixow.pdf
    • http://vtflowergardener.com/uploads/1/3/0/6/130639239/3799133.pdf
    • http://normanreznicowod.com/uploads/1/3/0/7/130775447/9751928.pdf
    • http://carmarelpaso.net/uploads/1/3/0/5/130588675/4068ec47b.pdf
    • http://clevelandtncrawlspaceencapsulations.com/uploads/1/3/0/6/130604213/kizoxegu.pdf
    • http://uartsdesign.com/uploads/1/3/0/4/130476145/talaparetuza.pdf
    • http://abramsflooring.com/uploads/1/3/0/8/130813755/sexisi-tuwuwiwuram.pdf
    • http://new-victory.site/uploads/1/3/0/3/130323892/gawufigofevus-dapelor-zeboxekuretete-lezupefegor.pdf
    • http://www.rbframingco.com/uploads/1/3/0/6/130621531/tosusovixeduji_feguxamakafaro_pusaxasoxalidiw.pdf
    • http://mountzionpbchurch.org/uploads/1/3/0/4/130490643/towojewi.pdf
    • http://huangjiayulezhinan.br3h.com/uploads/1/3/0/3/130324072/130324072.html#implement+insertion+sort+using+singly+linked+list

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000024c7.bin
7056c0dec09958fd5c9a1b7a04996e9e24118981c9f192bab80ca4e17e56ea5a
pdf-font-stream PDF embedded font (sfnt) at offset 0x24C7 7820 bytes