Malicious PDF — malware analysis report

Static analysis result for SHA-256 2506e64c756f0bbe…

MALICIOUS

PDF

43.6 KB Authoring application: Scribus
MD5: 194177fb8563036853dfc471a5f8b03b SHA-1: 6e6c7e833b96ffa36043ff924c9d9204f5dffe7e SHA-256: 2506e64c756f0bbe322d452e2b4f7769715fc920635a2eb585b35a904cd2fcae
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF files hosted on various domains, as indicated by the PDF_SEO_LINK_FARM heuristic. This suggests a phishing or SEO manipulation attack pattern. The ClamAV detection and ML classifier further support its malicious nature. No scripts were extracted from this sample, and the document body content is heavily truncated and unreadable, preventing a more detailed analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://amandabates.com/uploads/1/3/0/4/130435738/baponur-wifekijuwopikok.pdf
    • http://texomaitsolutions.com/uploads/1/3/0/7/130776219/9962179.pdf
    • http://www.thelandmark-condo.com/uploads/1/3/0/5/130588418/3fe902.pdf
    • http://minhavidaminhasescolhas.com/uploads/1/3/0/5/130543240/kumukelasapefor_xebom.pdf
    • http://www.royal-obrienclan-uk.org/uploads/1/3/0/5/130551687/485966.pdf
    • http://trainer.network/uploads/1/3/0/3/130313103/ruzaxafuza-tabovufigusij-jixijegem.pdf
    • http://mx.davideosellame.com/uploads/1/3/0/7/130775536/70f306c9.pdf
    • http://orsalus.net/uploads/1/3/0/6/130621135/d2490cb18c.pdf
    • http://xeebntxovjlee.com/uploads/1/3/0/6/130621503/zijuwarokowojipupi.pdf
    • http://dreamhatchery.com/uploads/1/3/0/4/130483043/zipojijefeloxuze.pdf
    • http://breckroadbc.com/uploads/1/3/0/4/130489052/4d6003c3.pdf
    • http://dougwessels.com/uploads/1/3/0/6/130621702/bijodive-keganetavutuk-nepaxisifofoxaz.pdf
    • http://bresumbrella.org/uploads/1/3/0/6/130639776/4154453.pdf
    • http://mynkylc.com/uploads/1/3/0/3/130379503/ab8036.pdf
    • http://pressburg-partners.com/uploads/1/3/0/5/130539987/47fdc7d.pdf
    • http://pointecoupeenow.com/uploads/1/3/0/6/130621814/9775876.pdf
    • http://registrationdogpapers.com/uploads/1/3/0/4/130435649/kalalomizuderurod.pdf
    • http://elizaandlarkin.com/uploads/1/3/0/4/130435622/7006312.pdf
    • http://apslabgroup.com/uploads/1/3/0/5/130546574/gudopulabopexu.pdf
    • http://benibiz.com/uploads/1/3/0/7/130739949/ad0a676.pdf
    • http://medrounds.net/uploads/1/3/0/6/130639275/xefigodaj.pdf
    • http://74-123-79-133.mgwnet.com/uploads/1/3/0/2/130273761/edd7e414d5d9d.pdf
    • http://chicklit.info/uploads/1/3/0/2/130274370/2603059.pdf
    • http://www.geminihomefragrance.co.uk/uploads/1/3/0/5/130588779/galigenu_jutezek_xuwefof_melazut.pdf
    • http://seapowermanagement.com/uploads/1/3/0/2/130270743/4930303.pdf
    • http://suppy-taiwan.com/uploads/1/3/0/6/130620490/130620490.html#oxford+english+dictionary+2nd+edition+online

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000349d.bin
1a31ae148aa4af7763392fe954e924425a92485837aa085ee7fbb165703794ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x349D 2636 bytes
font_01_sfnt_off0000410a.bin
d65aca64444bc892ff7c0e16c6d1449a2645425edcd3a6643d16451592523abd
pdf-font-stream PDF embedded font (sfnt) at offset 0x410A 9616 bytes