Malicious PDF — malware analysis report

Static analysis result for SHA-256 16682191dfedb8d2…

MALICIOUS

PDF

37.2 KB Authoring application: Poppler-utils
MD5: 2e0719e829ee929bc799d2bf33771d50 SHA-1: 56f8ceb7bec610be57ac3de97c08a14f478782ad SHA-256: 16682191dfedb8d2939708baf86aa054d2440450f975a211bae3a59a1563cef0
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file exhibits characteristics of a link farm or SEO manipulation, containing a large number of embedded URLs pointing to other PDF documents. The heuristic 'PDF_SEO_LINK_FARM' and the sheer volume of external links suggest an attempt to artificially inflate search engine rankings or distribute malicious content. While no scripts were directly extracted, the embedded URLs are the primary indicators of malicious intent, likely serving as a distribution mechanism for further payloads or phishing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://aikenkraft.com/uploads/1/3/0/7/130775166/7659139.pdf
    • http://myacollective.com/uploads/1/3/0/7/130739618/bufatu.pdf
    • http://aikenkraft.com/uploads/1/3/0/6/130639393/sudig.pdf
    • http://purplestore.org/uploads/1/3/0/8/130814421/tuwaratuxubulol.pdf
    • http://lexicon.edu.in/uploads/1/3/0/6/130603725/komixosis.pdf
    • http://noebrown.com/uploads/1/3/0/2/130288468/rogadeta.pdf
    • http://craigweflen.com/uploads/1/3/0/6/130640172/wawodatoj_fuloxoripogisal_jokojogowe.pdf
    • http://theladdsgroup.com/uploads/1/3/0/5/130588622/zodajokadu_gibok_medami.pdf
    • http://safedrivingschool.net/uploads/1/3/0/6/130604369/daduwogusagugim_winegatijo.pdf
    • http://sqonecondos.com/uploads/1/3/0/4/130490155/dadepivarufonu_wiwavir_gevidukojen_nexefa.pdf
    • http://rachaelhudes.com/uploads/1/3/0/7/130774973/mewejapibusol.pdf
    • http://buythef-ckingdip.com/uploads/1/3/0/4/130483478/8774f157.pdf
    • http://monstacartoons.com/uploads/1/3/0/5/130543798/3602766.pdf
    • http://spoonsleuth.com/uploads/1/3/0/7/130740371/7287465.pdf
    • http://bodysculptorsaustralia.com/uploads/1/3/0/6/130620168/lumafem-ragomari.pdf
    • http://bridgeequitiesadvisors.com/uploads/1/3/0/7/130740090/bajexusexogakedo.pdf
    • http://northcoastwalkingtours.com/uploads/1/3/0/6/130605094/2843086.pdf
    • http://iamcristinagarza.com/uploads/1/3/0/5/130538988/vitif_vawarifejifa.pdf
    • http://accidentattorneypocatello.com/uploads/1/3/0/3/130323936/eec86bede5.pdf
    • http://mail4.gisu.org/uploads/1/3/0/6/130639278/vevozasalorutudevibe.pdf
    • http://bottomlesshole.com/uploads/1/3/0/6/130621447/ludebugukor.pdf
    • http://norwalkunitedmethodistchurchiowa.com/uploads/1/3/0/4/130483263/baleti.pdf
    • http://lingbigyong.com/uploads/1/3/0/8/130814250/6715242.pdf
    • http://twelvethirtyfourfilms.com/uploads/1/3/0/7/130775835/digife_lafupude.pdf
    • http://74-123-72-229.mgwnet.com/uploads/1/3/0/6/130620228/130620228.html#verb+to+be+past+tense+exercises+pdf
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001b0c.bin
40a403f8312ff9c93041e514e965a4d57d797ba541f1da729710ef172887bfc2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B0C 16060 bytes
font_01_sfnt_off000031aa.bin
62b75b64691ac0737de632a8843b6c9e86a86e03eeabc9bc0ca8f6d84381c70f
pdf-font-stream PDF embedded font (sfnt) at offset 0x31AA 6448 bytes