Malicious PDF — malware analysis report

Static analysis result for SHA-256 326fa1eb700c8824…

MALICIOUS

PDF

46.3 KB Authoring application: Solid Converter PDF
MD5: 07b8fd8a19b6c5a13766b51682bd7320 SHA-1: 9e2cf1065128bfe6e7a3be04e5001d6ae7266d0d SHA-256: 326fa1eb700c88246b39675931d5f4f7593de064149f1880d65455b329d1c71d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to other PDF files hosted on various domains. This technique, identified as PDF_SEO_LINK_FARM, is commonly used to create link farms for SEO manipulation or to distribute malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body text is heavily obfuscated and does not provide clear user-facing content, but the overall structure points to a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://calsap.org/uploads/1/3/0/7/130776692/mivugovod_xorupuretugimoj.pdf
    • http://mymisssparkle.com/uploads/1/3/0/2/130287984/pavudufe-vipev.pdf
    • http://dzire2inspire.net/uploads/1/3/0/7/130775167/4058536.pdf
    • http://mikevincentphotography.net/uploads/1/3/0/7/130776241/8402356.pdf
    • http://natecleveland.net/uploads/1/3/0/7/130739983/jofafakerukowoje.pdf
    • http://arthurkillian.com/uploads/1/3/0/6/130603878/859107.pdf
    • http://barryboycephotos.com/uploads/1/3/0/6/130604497/gapefi.pdf
    • http://shopity.host/uploads/1/3/0/6/130640090/sejuxapufure.pdf
    • http://fairytalejourneysbywendy.com/uploads/1/3/0/8/130874540/kemokogepuv.pdf
    • http://35ewc.com/uploads/1/3/0/6/130604129/rodow-jemumujumabij.pdf
    • http://mobadanceacademyus.com/uploads/1/3/0/8/130814432/nanexumiwatizupufu.pdf
    • http://bartenderbitch.com/uploads/1/3/0/2/130270873/mironow_wigujapujowe_selutezuzodun.pdf
    • http://nailsbymargaret.com/uploads/1/3/0/7/130775704/reron.pdf
    • http://downforacure.org/uploads/1/3/0/4/130476697/61fbe64a27eb7.pdf
    • http://deluxefrenchfries.net/uploads/1/3/0/5/130588674/6502359.pdf
    • http://radjam.org/uploads/1/3/0/6/130639656/3c96c563d07c.pdf
    • http://threadsofthewayfarer.com/uploads/1/3/0/5/130588773/febitupujan-judawumavazem-tebesiwi-jovenafetusuwag.pdf
    • http://samuelyusuf.com/uploads/1/3/0/5/130550936/sokawojibir-lafemebod-tezezowaso-pugagu.pdf
    • http://ecarsindia.in/uploads/1/3/0/3/130312991/6629995.pdf
    • http://vantagepointchiro.com/uploads/1/3/0/7/130740364/bunasonizod-vorugafedita-navedapawabopo.pdf
    • http://portcharlottehomesforsale.net/uploads/1/3/0/3/130323979/wevuvurit_lazijurofuzugad_tibef_dewuzovoseriw.pdf
    • http://decentdecaf.coffee/uploads/1/3/0/5/130588805/tawibogi_ruwirejumi_lavadise_bumupogexuje.pdf
    • http://just2hearmyselftalk.com/uploads/1/3/0/6/130605244/ec518ea.pdf
    • http://oalkadi.com/uploads/1/3/0/5/130550803/2cd7cb10c05f.pdf
    • http://mountainandwaterstudio.com/uploads/1/3/0/6/130621719/difenuliwuf_xasulowigisama_zebifuwolegu.pdf
    • http://herlo.net/uploads/1/3/0/5/130550929/130550929.html#actuarial+exams+uk+2020

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004fa3.bin
9a598bd319a7d00fd38ee5985e4f35218df5f48ecf4c03c7be24145411c537ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x4FA3 8432 bytes