Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d4949cc9767b772…

MALICIOUS

PDF

56.1 KB Authoring application: Nitro PDF
MD5: 84720aa9ce3186e3ff54a624726f89c9 SHA-1: 0f20a5d0d277e07993c83458c983dd151a242edf SHA-256: 1d4949cc9767b772c23bab4d2be26dc2ac205e04fbff9bc4255f51b09a78cea7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a link farm with numerous external URLs, as indicated by the PDF_SEO_LINK_FARM heuristic. This suggests a phishing or SEO manipulation tactic. The ClamAV detection further confirms its malicious nature. No scripts were extracted from this sample, but the embedded URLs are the primary indicators of malicious activity.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bewaxojex.weebly.com/uploads/1/3/0/4/130494478/8119804.pdf
    • https://jadukekazonabis.weebly.com/uploads/1/3/0/5/130539944/662068daf31.pdf
    • https://rofigigesa.weebly.com/uploads/1/3/0/3/130323630/5080024.pdf
    • http://coasttocoasthauoratrust.com/uploads/1/3/0/5/130540683/jasavuximuti.pdf
    • https://latakegupus.weebly.com/uploads/1/3/0/5/130550931/05f304ca26.pdf
    • http://fatnsassysbooks.net/uploads/1/3/0/2/130272254/0afdef336.pdf
    • https://vimotubaguf.weebly.com/uploads/1/3/0/2/130270859/daxudud.pdf
    • http://pagefixile.diet-helper.club/uploads/2020/01/28/jokubim.pdf
    • http://beautelui.com/uploads/2020/01/27/texilonuzitebovizu.pdf
    • http://gituzomud.zagruzka7km.com/uploads/2020/01/29/97c5e35844d7b0b.pdf
    • http://vertoli.ru/uploads/2020/01/28/6254719.pdf
    • http://somersetfoodtrail.org/uploads/1/3/0/5/130590618/130590618.html#messi+vs+ronaldo+skills

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000130d.bin
e4a2940b2a26874b52ae25b26b3676c069ad6debbe10dc1d08c4a9d1379cb4b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x130D 8764 bytes
font_01_sfnt_off0000a053.bin
dc382466252a85a387eb55cc16884425ba0b9807757644430e481d876930b8ed
pdf-font-stream PDF embedded font (sfnt) at offset 0xA053 3184 bytes