Malicious PDF — malware analysis report

Static analysis result for SHA-256 32a60b5e4f2cf5f1…

MALICIOUS

PDF

36.1 KB Authoring application: PDF Studio
MD5: 9935d4cd6cf0d75c23ea0be4bc768f54 SHA-1: 7b282ad473ec23e2b828544ccd36e4903d0c67ed SHA-256: 32a60b5e4f2cf5f1fae81035973651bfbe97b3545b936038b3d0f4f480b6e9ff
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded external links, a common technique for SEO poisoning and phishing lures. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs likely lead to further malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://beltwayig.com/uploads/1/3/0/5/130539912/julesileludaniwarole.pdf
    • http://thenewmathclub.com/uploads/1/3/0/2/130272270/a2a48e65e.pdf
    • http://byblair.co/uploads/1/3/0/7/130776110/489564c.pdf
    • http://isellthis.net/uploads/1/3/0/8/130814112/8e7bf286907.pdf
    • http://mortalissar.com/uploads/1/3/0/4/130476272/3f12ac6174.pdf
    • http://natashawheinz.com/uploads/1/3/0/6/130621113/77971db11f70.pdf
    • http://mopola.com/uploads/1/3/0/5/130539637/94bd9c3991.pdf
    • http://nanoquests.com/uploads/1/3/0/7/130739475/af91b0.pdf
    • http://bartsbullets.com/uploads/1/3/0/6/130620989/0e36d628a.pdf
    • http://brc-management.com/uploads/1/3/0/5/130539244/8439048.pdf
    • http://blackwinghunting.com/uploads/1/3/0/6/130620420/5706366.pdf
    • http://24baltimore.com/uploads/1/3/0/5/130543305/288306.pdf
    • http://emailmarketing507.com/uploads/1/3/0/5/130539584/rosezodo.pdf
    • http://captainsclub.net/uploads/1/3/0/6/130639028/vunufez.pdf
    • http://anitaleverarttherapist.com/uploads/1/3/0/4/130477490/1959871c9a8.pdf
    • http://start3v1.ru/uploads/1/3/0/8/130815008/palod.pdf
    • http://step1.fun/uploads/1/3/0/4/130476766/fowuzebukusupukaji.pdf
    • http://mikeflattdesign.com/uploads/1/3/0/7/130775700/gidebaz-xumuwofubug-vapexafegax.pdf
    • http://mercywilder.com/uploads/1/3/0/4/130436271/pamiwutugufeme.pdf
    • http://zrvcgh.bdgct.com/uploads/1/3/0/4/130478374/130478374.html#adobe+illustrator+cs5+free+download+mac
    • http://isellthi

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003081.bin
233ab15e57b3e32e5c31c8445abdc5246b46eef24a49461b8f33a01d24da219a
pdf-font-stream PDF embedded font (sfnt) at offset 0x3081 7284 bytes