Malicious PDF — malware analysis report

Static analysis result for SHA-256 1823215dea13d512…

MALICIOUS

PDF

61.0 KB Authoring application: PDFedit
MD5: 26e4cb00f1919a8fc74d6698334b794a SHA-1: c472a417ac5e0e85b6f0a1af78a1566cabaaba82 SHA-256: 1823215dea13d512bcfe63d6f36294211341c67a039c5e11e5409ece6c3e1f15
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm of 11 external PDF files, suggesting a phishing or malicious redirection attempt. The embedded URLs are likely used to host or redirect to further malicious content, potentially leading to the download of additional malware. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://riverratkreations.com/uploads/1/3/0/5/130547576/584276.pdf
    • http://puppyuprising.com/uploads/1/3/0/2/130291478/b8af16587.pdf
    • http://rarabo.jetblue-air.com/uploads/2020/01/28/5673966.pdf
    • http://cvolierborgerhout.com/uploads/1/3/0/4/130435639/8672537.pdf
    • http://youbling.weebly.com/uploads/1/3/0/6/130639836/topipiso.pdf
    • http://techconnectwest.net/uploads/1/3/0/5/130546593/9805051.pdf
    • http://superstarstruck.weebly.com/uploads/1/3/0/4/130476317/6409979.pdf
    • http://nyclanguageinstitute.com/uploads/1/3/0/4/130476859/ranuxubolela-fivijux-xoporazitosifig-doxagarigogoz.pdf
    • http://321cero.net/uploads/2020/01/27/4272400.pdf
    • http://balance4yourlife.com/uploads/1/3/0/6/130639547/66647520c5.pdf
    • http://xowf.com/uploads/1/3/0/6/130639875/sosogo_pilenepaf.pdf
    • http://san69.com/uploads/1/3/0/6/130605325/130605325.html#jeep+grand+cherokee+service+manual+p

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000132c.bin
23e1244d008cf7643fd10fb7ee05a40b122816c4f4bdb2f6315dae128925b4b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x132C 8936 bytes