Malicious PDF — malware analysis report

Static analysis result for SHA-256 1deed022644e47e5…

MALICIOUS

PDF

28.7 KB Authoring application: pdf-parser
MD5: 5405713da98cc937d6314d706f2dd919 SHA-1: 1cea8b9672611416828093c4402fc34cca9f790b SHA-256: 1deed022644e47e5c4c7e50f418a7066fa4afce22697b5ebf60e2dd48283965e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was detected by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0. Static analysis revealed a large number of embedded external links, characteristic of SEO spam or phishing campaigns. The primary heuristic firing indicates a PDF link farm, suggesting the document's purpose is to distribute traffic to numerous external URLs, likely for malicious purposes.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rosso-levanto.ru/uploads/2020/01/28/6305308.pdf
    • http://apostolicadventures.com/uploads/1/3/0/4/130476308/3784587.pdf
    • http://lascyclitas.com/uploads/1/3/0/6/130605442/1c059ac50c.pdf
    • http://weopenshows.com/uploads/1/3/0/5/130544295/metup.pdf
    • http://amicabletrust.org/uploads/1/3/0/6/130605412/lejokewaken.pdf
    • http://gosendme.us/uploads/1/3/0/6/130604349/gujatofopazobut_fetaboburi_nivanepazew.pdf
    • http://professorstylz.com/uploads/1/3/0/6/130620406/barudevidoni_fazase_jokapilode.pdf
    • http://rod.fineinfo.ru/uploads/2020/01/27/c9c3206cd33.pdf
    • http://fresco40.ru/uploads/2020/01/27/e7909026d28b1f.pdf
    • http://fofagofa.horizon-geo.com/uploads/2020/01/27/papafebudi.pdf
    • https://petazewofenirir.weebly.com/uploads/1/3/0/5/130539659/guvunare-perakuvifeleb.pdf
    • http://rav.3f9d7d34b1371af6edffdafb9e4db3a9.com/uploads/2020/01/28/2678551.pdf
    • http://chickadeerevisions.com/uploads/1/3/0/5/130544136/6ad7144b.pdf
    • http://mariettasquarefarmersmarket.net/uploads/1/3/0/6/130639948/130639948.html#reporting+anova+results+in+table+format

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012ac.bin
f55902356819b0a6e2a3581c4077aec6e424e564aea8341c08b22368ec31e219
pdf-font-stream PDF embedded font (sfnt) at offset 0x12AC 6616 bytes