Malicious PDF — malware analysis report

Static analysis result for SHA-256 3628bb678186a933…

MALICIOUS

PDF

42.2 KB Authoring application: OpenOffice Draw
MD5: f1f64c3af0d6442e910cc2e473016448 SHA-1: d4825f5492d18cd1af6c9322ec70833829e6badf SHA-256: 3628bb678186a9339bd3c2d11711ef0ac82b0aca7f09fdd19a4aded29af34e79
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents, a technique often used for SEO spam or to distribute malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body is heavily corrupted, but the presence of numerous URLs points to a link farm or redirection strategy.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://andrianaediting.ca/uploads/1/3/0/5/130589416/roregudabipidage.pdf
    • http://m31.systems/uploads/1/3/0/6/130605179/3303310.pdf
    • http://birkdaleawards.com/uploads/1/3/0/6/130604386/depawerokumozaf-tuzuwaxerox-zafor-jekupatidavo.pdf
    • http://star-nrg.com/uploads/1/3/0/6/130639021/5995744.pdf
    • https://zupudirepizogob.weebly.com/uploads/1/3/0/4/130488446/depijekeki-parobamame-netaxapa.pdf
    • http://buse.seowallet.ru/uploads/2020/01/27/1799151.pdf
    • http://bulavu.0406shopps04.fun/uploads/2020/01/29/puzewif-zotaduxi-lemex.pdf
    • http://alpharettapestpros.com/uploads/1/3/0/5/130544386/naxeve.pdf
    • http://kil.digitalein.com/uploads/2020/01/28/xonimogenev.pdf
    • http://dokenina.1-gc.biz/uploads/2020/01/28/moxaruwogotaj-nizonam-wolivu-nesusaropo.pdf
    • http://lovim.info/uploads/2020/01/28/nevubuxake-basorilup.pdf
    • http://luadantuong.com/uploads/2020/01/28/zozava-lapininer.pdf
    • http://myentouragemusic.com/uploads/1/3/0/4/130435547/130435547.html#arrival+movie+free++mp4

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000135e.bin
00c4d8ab0d77c491f1dcebad7fc2f2b108b912dc7ceb70f434697e7478f8961a
pdf-font-stream PDF embedded font (sfnt) at offset 0x135E 9000 bytes
font_01_sfnt_off00005bf3.bin
cf221213b2a0eb24b017e68b9e2ebe053727bc9a9d95611ed39b1e9bd298f7bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x5BF3 16888 bytes