Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ccef93b06563b67…

MALICIOUS

PDF

36.5 KB Authoring application: QPDF
MD5: d95d4fbd82223e92332d7ed7f9828169 SHA-1: 8ccfbdfbff44bdcc97f4c7030acab92a8d688732 SHA-256: 2ccef93b06563b67f6de163fde1926f1ae64e530c2fb55349ea850a40dac0976
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links, a common technique for phishing and malware distribution. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The document body, though heavily corrupted, appears to be a lure, attempting to present itself as a legitimate PDF download for medical procedures, while the embedded URLs lead to a link farm of other PDF files, likely serving as a distribution mechanism for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://riotthink.com/uploads/1/3/0/5/130538946/litelopapuk.pdf
    • http://addycakescookies.com/uploads/1/3/0/5/130541402/sarokobixamagafar.pdf
    • http://quaternityoga.com/uploads/1/3/0/2/130272609/vebatuzepemarufuj.pdf
    • http://thebynumagency.com/uploads/1/3/0/5/130590535/1a1399d4bd.pdf
    • http://abcofscotland.com/uploads/1/3/0/7/130738831/fa0283f8c97def.pdf
    • http://isecmitigationgroupllc.com/uploads/1/3/0/3/130313262/wojita-tomiki.pdf
    • http://ctmpropertymanagementsc.com/uploads/1/3/0/7/130740318/5574841.pdf
    • http://adisera.com/uploads/1/3/0/6/130640074/559e117923.pdf
    • http://namyangitaly.com/uploads/1/3/0/5/130588473/zonebopabopeji.pdf
    • http://winecountryreclaimedfurniture.com/uploads/1/3/0/6/130639309/tikeferazep.pdf
    • http://flashissuemail.net/uploads/1/3/0/3/130313471/b9fd91ffb78f9b.pdf
    • http://host59.carmichaelnl.com/uploads/1/3/0/6/130604344/130604344.html#roberts+and+hedges%E2%80%99+clinical+procedures+in+emergency+medicine+and+acute+care+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002bf7.bin
83459e82cebe561b9e65dda6a09953c9e35f75e5df0fa62a624e1833cc5b8086
pdf-font-stream PDF embedded font (sfnt) at offset 0x2BF7 1708 bytes
font_01_sfnt_off00003713.bin
cb50fd0330f67f9721fa99bbd13bd4763f4534bcc46d0ab3e08462ebad18238a
pdf-font-stream PDF embedded font (sfnt) at offset 0x3713 7932 bytes