Malicious PDF — malware analysis report

Static analysis result for SHA-256 363bccc09a659667…

MALICIOUS

PDF

34.8 KB Authoring application: PDF Studio
MD5: 7a83dcb5a06e8aaa2ea472097b1ec0ab SHA-1: 93e5a2ea7823ec79e3077d62e822c8de0e5ab5ca SHA-256: 363bccc09a6596675e5aa6f6512c2e81ec251de52763a292c7fd3969e1ddec1e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF files hosted on various domains, indicating a link farm or redirection scheme. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic redirection intent. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery mechanisms.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://belleajai.com/uploads/1/3/0/5/130541846/bipuvem_tobajejibiji_fekuru.pdf
    • http://www.prodbyq.com/uploads/1/3/0/3/130313289/bozofikekulelasezuka.pdf
    • http://www.katarinatuffvesonjensen.com/uploads/1/3/0/5/130590548/sadum.pdf
    • http://www.explore-create.com/uploads/1/3/0/5/130550960/novugoregojigug.pdf
    • http://rickyzheng.net/uploads/1/3/0/8/130814040/d0576ed2196c.pdf
    • http://streamboxtv.com/uploads/1/3/0/5/130589342/kiluzowaladu.pdf
    • http://myezpzpay.com/uploads/1/3/0/3/130313826/6426012.pdf
    • http://munciearts.net/uploads/1/3/0/4/130490117/1286022.pdf
    • http://cleaningclinic.shop/uploads/1/3/0/7/130775688/6905661.pdf
    • http://natashadoulabirthmarks.com/uploads/1/3/0/7/130738564/dezapaf.pdf
    • http://nongress.org/uploads/1/3/0/4/130478106/3452428.pdf
    • http://doctorberrycoaching.com/uploads/1/3/0/2/130289424/8535438.pdf
    • http://rickandjudy.net/uploads/1/3/0/4/130483147/9b07e31.pdf
    • http://sweetwillowsoap.com/uploads/1/3/0/7/130739155/bufarufokeben.pdf
    • http://lovebirthlondon.com/uploads/1/3/0/5/130543038/674b4a4a0.pdf
    • http://millymop.co.uk/uploads/1/3/0/4/130488503/8338891.pdf
    • http://thebusinesstip.com/uploads/1/3/0/4/130476502/130476502.html#lower+abdominal+cramps+from+gas
    • http://sweetwillowsoap.com/uploads/1/3/0/7/130739155/bufarufoke

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002cf8.bin
60a2a7fd2fb9ee17aa89f07e7ab5174ef9604a4c67468f898853b0abc2bdb9ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x2CF8 7700 bytes