Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bf409420c744c78…

MALICIOUS

PDF

40.0 KB Authoring application: Scribus
MD5: 17ff96f2f0263503b23e9fdeab5fc6a9 SHA-1: 3092c928a3d544fcb369b86420a55dedfbbad637 SHA-256: 2bf409420c744c78c230ba1e324bae86dd6e3dafd21c5872e70239554993b564
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to other PDF files, indicating a link farm designed to redirect users. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly suggest malicious intent. The heuristic 'PDF_SEO_LINK_FARM' confirms the presence of numerous external links, with 'redmonsterconsulting.com' being a dominant host. No scripts were extracted, but the structure and URL distribution are indicative of a phishing or redirection campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://redmonsterconsulting.com/uploads/1/3/0/6/130621776/8561786.pdf
    • http://murphcooper.com/uploads/1/3/0/6/130605196/fakemitefowogu.pdf
    • http://mmalifestyler.com/uploads/1/3/0/7/130776105/ruwepoxeri-zizizano-vawiketuwowodat.pdf
    • http://jetherington.com/uploads/1/3/0/7/130776351/zurebavixax-basilozatasu.pdf
    • http://constancehsb.com/uploads/1/3/0/8/130814515/dbd53a7e5754.pdf
    • http://errqre.com/uploads/1/3/0/2/130291531/bc22e73d6ff9.pdf
    • http://geigerair.com/uploads/1/3/0/7/130740183/3512001.pdf
    • http://cmtrader.net/uploads/1/3/0/8/130874222/e3e45d673c.pdf
    • http://seasonalswap.com/uploads/1/3/0/7/130739132/mibewow.pdf
    • http://www.teen-works.com/uploads/1/3/0/4/130476505/3b0bbc31de.pdf
    • http://sheilaberger.com/uploads/1/3/0/7/130776336/raxerulativat.pdf
    • http://www.kennyosborne.com/uploads/1/3/0/2/130289682/1761f11ee127e.pdf
    • http://zyonstrategies.com/uploads/1/3/0/3/130379504/4c9ecfd902873e.pdf
    • http://thehealthychocolateshop.com/uploads/1/3/0/2/130289734/2244483.pdf
    • http://coachharrisbiologywebsite.com/uploads/1/3/0/4/130488547/zegibaxitumi_lamak_toxebopab_bawinano.pdf
    • http://mail.mypersuasions.com/uploads/1/3/0/2/130287296/4022792.pdf
    • http://lunaparkstudio.net/uploads/1/3/0/5/130588928/sezakilodo.pdf
    • http://tourbillonart.com/uploads/1/3/0/5/130551130/soxatexepijatirasas.pdf
    • http://pittmanguitars.com/uploads/1/3/0/5/130542728/8059333.pdf
    • http://osbaonline.com/uploads/1/3/0/8/130874648/xulinigi_jezizafifovafiz_vuridejup.pdf
    • http://micrusade.com/uploads/1/3/0/4/130483204/4686858.pdf
    • http://jaxalphabetphoto.com/uploads/1/3/0/5/130550741/nafititesikimuk_luxonasenok_nejaped.pdf
    • http://dux-plex.com/uploads/1/3/0/5/130551287/nulomunalifedarexi.pdf
    • http://74-123-72-189.mgwnet.com/uploads/1/3/0/5/130540214/130540214.html#occipital+nerve+block+trigger+point+injection
    • http://thehealthychocolateshop.com

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002dee.bin
0efc485bfecffc3e9ad601ef019a4ed7c4acd3ce5dcf48e6d21f45b21f0bad0f
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DEE 1576 bytes
font_01_sfnt_off0000384c.bin
1ab94cd3236c4286dd189d063ec816bc8d0ea3d7ef1ea0c7fc04be0efcb076d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x384C 8268 bytes