Malicious PDF — malware analysis report

Static analysis result for SHA-256 223985170669d284…

MALICIOUS

PDF

44.8 KB Authoring application: Adobe PDF Library 9.0
MD5: ea39ed1239880fd7d59342e895343de2 SHA-1: 3f120aa7f2c9228e7555b6b1d56d06a5133ccb21 SHA-256: 223985170669d284d8591f6a4cc15d78dd4bfbce7118e112e888bbdd583b3424
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple heuristics, including a critical finding for a link farm containing 18 external links. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output of 0.999937 further support its malicious nature. The embedded URLs are likely used to redirect users to phishing sites or download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nvution.fun/uploads/1/3/0/2/130274076/tasisejixefuda.pdf
    • http://davebecker.org/uploads/1/3/0/2/130289652/413896.pdf
    • http://mobileplantmanagement.com/uploads/1/3/0/6/130621707/28fa16d667fe.pdf
    • http://normandyoptical.biz/uploads/1/3/0/6/130605206/9077148.pdf
    • http://menschwork.com/uploads/1/3/0/6/130604740/1538800.pdf
    • http://simplicityaccountingllc.com/uploads/1/3/0/5/130546645/e676804e.pdf
    • http://gesimanug.skiandtraks.com/uploads/2020/01/28/9294411.pdf
    • http://naturalproducts.shop/uploads/1/3/0/2/130287971/rovipipujufosipodise.pdf
    • http://birdislandplacenciabz.com/uploads/1/3/0/2/130289296/garijugiruleduge.pdf
    • http://momentumlifecoach.org/uploads/1/3/0/4/130476974/130476974.html#eos+600d+manual+focus

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001270.bin
5f4c43bf0040c96c3a10c70f25de53c230430a26c781d5562d572cfd1be54b0b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1270 8824 bytes