Malicious PDF — malware analysis report

Static analysis result for SHA-256 15e6f36d1e9f1e77…

MALICIOUS

PDF

39.5 KB Authoring application: Karbon
MD5: fca50ec69d9564e5e1513d96e873a6cc SHA-1: 8361e9e54e43eb8319eb1f8f0506c3a857608efc SHA-256: 15e6f36d1e9f1e77459411478d7c785aa4c118379718866a783fa1b6ea6b0856
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links to external PDF files hosted on various domains, indicative of a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly suggest malicious intent, likely to distribute further content or engage in phishing. No scripts were extracted, but the embedded URLs are the primary indicators of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ontherolljoplin.com/uploads/1/3/0/7/130738487/6068247.pdf
    • http://yasinrahim.com/uploads/1/3/0/6/130621225/751b7f508cfb1.pdf
    • http://bestself.studio/uploads/1/3/0/5/130545475/1275931.pdf
    • http://mootsmarketing.com/uploads/1/3/0/5/130550995/50297832bf4bd0.pdf
    • http://xop.defki.icu/uploads/2020/01/29/6172296.pdf
    • http://0206shop04.fun/uploads/2020/01/28/bofabiw.pdf
    • http://busuxan.seo-spytnik.ru/uploads/2020/01/28/7113865.pdf
    • http://fixing.team/uploads/1/3/0/6/130639936/1668474.pdf
    • http://poppies-daycare.co.uk/uploads/1/3/0/5/130539702/xeteban.pdf
    • http://colddiamnd.com/uploads/1/3/0/5/130590664/130590664.html#bbc+porn+hd

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000116e.bin
262231c9c4257217db6cefc793bc3aeb5859512ea53dab308d13ab73c1376560
pdf-font-stream PDF embedded font (sfnt) at offset 0x116E 7808 bytes