Malicious PDF — malware analysis report

Static analysis result for SHA-256 112eff531166336f…

MALICIOUS

PDF

37.6 KB Authoring application: Soda PDF
MD5: 81d9307be05ba72d2cbca0591f0a72e8 SHA-1: aaa97e55c7acdbce03b0d82112ad25546dc62d4e SHA-256: 112eff531166336f4adcf541254624f1664f5c6bc05d049455d9a2e0668e88aa
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, a technique often used for SEO spam or to redirect users to malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to leverage external resources for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://theduiskeinn.com/uploads/1/3/0/6/130639766/1ee422677a.pdf
    • http://philipejike.com/uploads/1/3/0/5/130539672/c3a29.pdf
    • http://psychastar.com/uploads/1/3/0/5/130545627/fb234919d52.pdf
    • http://boujeebbeauty.com/uploads/1/3/0/5/130539934/c7efdcfe0abdc.pdf
    • http://eurovisual2015.com/uploads/1/3/0/6/130621206/gizekazilikel.pdf
    • http://drbrewer.net/uploads/1/3/0/4/130483667/0c7c86c.pdf
    • http://nadiajanssens.weebly.com/uploads/1/3/0/2/130292110/mezilemonof_teduwimuforij.pdf
    • http://northernlightscoaching.net/uploads/1/3/0/5/130543665/1967449.pdf
    • http://xile.omgnew168.com/uploads/2020/01/27/1e0e6.pdf
    • http://overlookatlindberghfinancing.com/uploads/1/3/0/3/130313262/valasikew_betegi_topomoto_wisijan.pdf
    • http://astrologyandcrystallighttherapy.com/uploads/1/3/0/5/130543168/6667805.pdf
    • http://nupelicanparty.org/uploads/1/3/0/3/130313070/130313070.html#multiplication+and+division+of+mixed+fractions+worksheets
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012e7.bin
af0681ae22f4d060aae6f2831aa41c40d962edc7976c839162aa1961b661b4de
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E7 7832 bytes
font_01_sfnt_off00005746.bin
e2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea
pdf-font-stream PDF embedded font (sfnt) at offset 0x5746 2652 bytes