Malicious PDF — malware analysis report

Static analysis result for SHA-256 32df3d55614b2d63…

MALICIOUS

PDF

48.4 KB Authoring application: Scribus
MD5: 94041eadaecf3b27856e93a791e45395 SHA-1: 5a53c2426fa984210c22553d14568a1674ab39a7 SHA-256: 32df3d55614b2d637bbd92aa725a02d38e7dac2b8663c7142927e89f4da676ea
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection as Pdf.Phishing.TtraffRobotInstall-7605656-0 further supports a malicious intent. The primary goal appears to be directing users to a vast array of external PDF files, likely for SEO spam or phishing campaigns.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bonkerforbyram.com/uploads/1/3/0/6/130604022/51af6bdab48f9c6.pdf
    • http://summershoppingspree.com/uploads/1/3/0/7/130739619/7301848.pdf
    • http://kpsmusik.com/uploads/1/3/0/3/130312913/5493431.pdf
    • http://mikacollins.com/uploads/1/3/0/5/130589433/026bee1976d2bc.pdf
    • http://soundnotion.tv/uploads/1/3/0/5/130551475/27fc8c44c.pdf
    • http://kingscredit.org/uploads/1/3/0/6/130621740/bajetanabufow.pdf
    • http://edclarkesound.com/uploads/1/3/0/6/130639554/3850920.pdf
    • http://mindandhomeinsurance.com/uploads/1/3/0/6/130620620/kazuritawuminire.pdf
    • http://pragmex.com/uploads/1/3/0/4/130483953/3596079.pdf
    • http://lawncarebenton.com/uploads/1/3/0/7/130776336/felurigij-juvokovimekeb.pdf
    • http://cabinaselshaddai.com/uploads/1/3/0/6/130605040/c7ddb8.pdf
    • http://127onyork.com/uploads/1/3/0/4/130435966/94887a89b69be8.pdf
    • http://bewnanskernow.org/uploads/1/3/0/7/130776027/rukuxesezefogu.pdf
    • http://hasiam.com/uploads/1/3/0/6/130604556/9138579.pdf
    • http://village-life.com/uploads/1/3/0/3/130379528/gixejuronopate.pdf
    • http://bestfriendsbakery.net/uploads/1/3/0/8/130813616/2745211.pdf
    • http://3dfreeze.com/uploads/1/3/0/5/130589195/7042134.pdf
    • http://wayjayjetwas.com/uploads/1/3/0/2/130288397/pamiruwuvuko.pdf
    • http://adairwatkins.com/uploads/1/3/0/6/130639463/1678703.pdf
    • http://minechivor.net/uploads/1/3/0/6/130640179/veropekisu_vewuxedupadepi_raxapet.pdf
    • http://kwpetcarecypress.com/uploads/1/3/0/5/130545753/bixikefunifolilog.pdf
    • http://krazy-verns-carwash.com/uploads/1/3/0/2/130270898/janowivako.pdf
    • http://93ugs.salon225.com/uploads/1/3/0/5/130588830/130588830.html#type+hindi+using+english+keyboard+ms+word

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000036ec.bin
78116880e9c902c31767bfa12a9ff84ada309181a52ab1aa29cdf6fbfe115b45
pdf-font-stream PDF embedded font (sfnt) at offset 0x36EC 2600 bytes
font_01_sfnt_off000040a5.bin
2db29711b7f0d48befb7b9feee4216e98af9f5ed49d377ea6eee72f330f88564
pdf-font-stream PDF embedded font (sfnt) at offset 0x40A5 9572 bytes
font_02_sfnt_off00005cac.bin
22cf4382982b5617b1d0696447996f73bfe6ca9893426d6adcfe5555a67749de
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CAC 7652 bytes