Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b7d3c41a62c2c0d…

MALICIOUS

PDF

76.7 KB Authoring application: Mobipocket Creator
MD5: 51a7e2560fe4017f6efd6efe7e8f146e SHA-1: ab5549f3a6ca3dd66c689e6f2501b5dbfdddb01f SHA-256: 2b7d3c41a62c2c0d02e668910d5b04109d61dca654aa602fbb1197b323060329
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. ClamAV also detected this file as Pdf.Phishing.TtraffRobotInstall, indicating a phishing or traffic-generation intent. The embedded URLs likely lead to further malicious content or phishing pages. No scripts were extracted from this sample.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.realfinancialcoach.com/uploads/1/3/0/6/130604320/nixurez-tukep.pdf
    • http://chadallers.com/uploads/1/3/0/6/130639875/xejemelizidum_ketiwokogap.pdf
    • http://createpowtoon.com/uploads/1/3/0/3/130313220/mewevudozogos_rawokamazema_supoxu.pdf
    • http://elizabethbrowndesign.com/uploads/1/3/0/7/130775833/1284885.pdf
    • http://catering.abc.it/uploads/1/3/0/7/130776536/106c23e545c.pdf
    • http://nuezdejabon.com/uploads/1/3/0/2/130287514/1698651.pdf
    • http://zuada.org/uploads/1/3/0/5/130588907/sesuzugokaverog.pdf
    • http://buysellbell.com/uploads/1/3/0/7/130775862/5032493.pdf
    • http://weilerandborst.com/uploads/1/3/0/7/130739210/xezunexezexip_pinijobolupifo_puwax.pdf
    • http://helenshanks.org/uploads/1/3/0/7/130739766/7540943.pdf
    • http://www.creditschooltuescueladecredito.com/uploads/1/3/0/5/130551704/novibofodawope_tukalufupabewav_rogimi.pdf
    • http://www.lucianaluna.com/uploads/1/3/0/3/130313294/pepuwopesegubunamepi.pdf
    • http://mail2.gandpdesigns.com/uploads/1/3/0/9/130969498/nepijavas-bopir-fugur.pdf
    • http://www.ancilliaryconsultinggroup.com/uploads/1/3/0/6/130603855/7830713.pdf
    • http://workingclasskids.com/uploads/1/3/0/4/130435909/kumigasowukidebus.pdf
    • http://arkstore.shop/uploads/1/3/0/7/130738821/panijebuson-novavurapawe.pdf
    • http://bearsvsbabiesgame.net/uploads/1/3/0/2/130274291/7803658.pdf
    • http://nazga.org/uploads/1/3/0/6/130620154/rojaminixulap_maxavajusaw.pdf
    • http://northalabamavinylspecialists.com/uploads/1/3/0/6/130604517/pigemanidulasoz.pdf
    • http://slightedgedesign.com/uploads/1/3/0/2/130289519/3162388.pdf
    • http://www.iowabirthactivists.org/uploads/1/3/0/4/130476086/e3eb22215.pdf
    • http://www.selenialimited.com/uploads/1/3/0/6/130603747/7727400.pdf
    • http://suzanne-bond.org/uploads/1/3/0/4/130478760/lofigisil.pdf
    • http://mingateachers.com/uploads/1/3/0/7/130738629/suxusekumumuzixa.pdf
    • http://mgeducationfund.org/uploads/1/3/0/5/130551684/5251379.pdf
    • http://webmail.gammaxiques.org/uploads/1/3/0/4/130488227/130488227.html#html5+embed+pdf

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003203.bin
1b3f82cd74c5b6671cc0c0d4a6c7877b74bb57ca469b2a61ef541918e41af838
pdf-font-stream PDF embedded font (sfnt) at offset 0x3203 2652 bytes
font_01_sfnt_off00003f15.bin
68398ad25d6ae2d5782061c34e4c79e7811746959f3c91a565b678fa1dcd66cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x3F15 44100 bytes
font_02_sfnt_off0000c5a8.bin
8ba228cfde4a2106d501216aebec2d036464a88c4c94d895e0f933a77f3d36b4
pdf-font-stream PDF embedded font (sfnt) at offset 0xC5A8 9288 bytes