Malicious PDF — malware analysis report

Static analysis result for SHA-256 304018a345e62b87…

MALICIOUS

PDF

44.9 KB Authoring application: Poppler-utils
MD5: d10a54435534e899f209f4fdc83947c2 SHA-1: f1174c5882a89d47162d9c05a3b02279c21a38a6 SHA-256: 304018a345e62b873e58fcbdb53f147f269031c4236bd0febda054b8f609ab8e
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files hosted on various domains, indicating a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or distributing further malware. No scripts were extracted, and the document body is heavily obfuscated, but the sheer volume of outbound links is the primary indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mikkiscreations.shop/uploads/1/3/0/2/130274368/8513428.pdf
    • http://batazakek.pulkovo3.info/uploads/2020/01/27/1162542.pdf
    • http://77thscouts.ca/uploads/1/3/0/4/130477310/1369588.pdf
    • http://1113studios.net/uploads/1/3/0/5/130551981/fewikev.pdf
    • http://wabashtees.com/uploads/1/3/0/4/130488331/napedudav.pdf
    • http://shopamysattic.net/uploads/1/3/0/5/130552034/1df2ef4b30a6.pdf
    • http://shannonsharper.com/uploads/1/3/0/3/130379818/ea32b88325e2.pdf
    • http://purebarretexasstrong.com/uploads/1/3/0/5/130551343/5220379.pdf
    • https://pomanipusutuluw.weebly.com/uploads/1/3/0/5/130539305/c3f96b.pdf
    • http://mrbojandals.com/uploads/1/3/0/4/130435857/cfa42c7635c.pdf
    • http://oasistoyhaulers.com/uploads/1/3/0/5/130551651/tinudurofin.pdf
    • http://mindforyouth.com/uploads/1/3/0/6/130639082/40642828d.pdf
    • http://regenesisgroup.net/uploads/1/3/0/6/130604938/rutadubuzitif.pdf
    • http://blackoakcreativetest.com/uploads/1/3/0/2/130271132/2c22ce26dd4.pdf
    • http://dad.tht-premiere.online/uploads/2020/01/27/xudetasuzelobulutis.pdf
    • http://auroraweddingandevents.co.uk/uploads/1/3/0/2/130272086/rilijuvatuto.pdf
    • http://thealth.ru/uploads/2020/01/27/730e8fd68.pdf
    • http://ackertech.org/uploads/1/3/0/6/130621305/afee8acc29e4c.pdf
    • http://aprendizajeactivobrumiel.com/uploads/1/3/0/4/130483836/130483836.html#can%27+t+format+sd+card+mac+os

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000014fd.bin
b9cb24f76559253ebc3368985fe86a8b4a0190d762fb7af54d780f4f9ecb4cba
pdf-font-stream PDF embedded font (sfnt) at offset 0x14FD 8356 bytes
font_01_sfnt_off0000676e.bin
ac49849b978058f48725d089179747450f7987fdfd4cddbc63fac11af8b99083
pdf-font-stream PDF embedded font (sfnt) at offset 0x676E 16384 bytes