Malicious PDF — malware analysis report

Static analysis result for SHA-256 331c373d0f27fd0e…

MALICIOUS

PDF

104.2 KB Authoring application: Nitro PDF
MD5: 7834478eff23abf4c6f8d85ce15a6ab0 SHA-1: 7bb34233d8e4fb03ac754e762d3daabe17df0bf6 SHA-256: 331c373d0f27fd0e5c50f440ed934060c5502f645015ba01d8d21ebe92d312f1
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links pointing to external PDF files hosted on various domains. This technique is often used for SEO poisoning or to redirect users to phishing sites or malware downloads. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection intent. No scripts were extracted from this sample.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.benszen.com/uploads/1/3/0/2/130289663/buvemupugo.pdf
    • http://cvillehomeimprovements.com/uploads/1/3/0/3/130379354/ragizidopimokav.pdf
    • http://graniteconsultingnh.com/uploads/1/3/0/6/130604644/0a9ff176245e0.pdf
    • http://alwingchun.com/uploads/1/3/0/2/130270847/wovuwarul-melilidoxa-mudomej-samiziwunijotib.pdf
    • http://www.hairden.org/uploads/1/3/0/6/130639438/f2781b0b05.pdf
    • http://campkennedy.com/uploads/1/3/0/7/130739443/8771201.pdf
    • http://www.firstclasscp.com/uploads/1/3/0/8/130813489/9550655.pdf
    • http://mindfuldemocracy.org/uploads/1/3/0/5/130588796/6526192.pdf
    • http://www.legacywebdesign.ca/uploads/1/3/0/4/130488213/todewi.pdf
    • http://www.vagrantman.com/uploads/1/3/0/6/130605389/dopamokap-putebezev-finulowu-tudijexobaru.pdf
    • http://thebighooyah.com/uploads/1/3/0/2/130272921/setufijisemepad.pdf
    • http://myeduzone.org/uploads/1/3/0/4/130479435/bizupavotejerupi.pdf
    • http://beautyefx.com/uploads/1/3/0/2/130289736/1766945.pdf
    • http://mikeandeli.nyc/uploads/1/3/0/3/130323738/zavabadovog_niwelutisakose_bafos.pdf
    • http://mail.interactivecapitalgroup.com/uploads/1/3/0/2/130270873/gazekitawe-sawuwanaku.pdf
    • http://perrymeridianyouthbb.com/uploads/1/3/0/7/130739500/5342671.pdf
    • http://downriverkaraokeanddj.com/uploads/1/3/0/6/130621066/1d5556ebfde.pdf
    • http://parentalrightsmovement.org/uploads/1/3/0/7/130775905/14d1af1.pdf
    • http://gadgetprices.com/uploads/1/3/0/6/130604269/rubuje_gojonajedalupi_bimemowol.pdf
    • http://naturalkinksinthecreek.com/uploads/1/3/0/6/130620948/saponeradavef-lomeladusug.pdf
    • http://ilafayette.net/uploads/1/3/0/6/130621772/fofugotiz-nuvisuzafivep.pdf
    • http://sunrise.activitydaily.com/uploads/1/3/0/5/130588571/fb856d6f76.pdf
    • http://www.classicseiko.com/uploads/1/3/0/7/130775888/7928724.pdf
    • http://rcaleel.com/uploads/1/3/0/7/130740128/tejab.pdf
    • http://thegeorgiaquailhunt.com/uploads/1/3/0/7/130775462/xetoge.pdf
    • http://weatherproofguide.com/uploads/1/3/0/6/130603956/130603956.html#amar+ujala+news+paper+in+hindi+today+up+moradabad

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000029f6.bin
04c2411718632844ea989149718a96bb458046b2133bfbe14ba7363360b20767
pdf-font-stream PDF embedded font (sfnt) at offset 0x29F6 17316 bytes
font_01_sfnt_off000058a1.bin
fd61ff72f0c74c6dd9bf87a28160fe2e2391b0965186090865c9132cd411dfca
pdf-font-stream PDF embedded font (sfnt) at offset 0x58A1 7740 bytes
font_02_sfnt_off000161d3.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x161D3 1388 bytes