Malicious PDF — malware analysis report

Static analysis result for SHA-256 3686bb65b3bcc1c3…

MALICIOUS

PDF

35.4 KB Authoring application: Poppler-utils First seen: 2020-09-24
MD5: 47f123712d3393adbbdd919740f9e278 SHA-1: 1c86b03de5c8180fa13f4ebb3a22a023280cc304 SHA-256: 3686bb65b3bcc1c3d4de91c66a802c0bd7117b85f9f61d66ad2328c4a2574604
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm designed to distribute malicious content. ClamAV detection as Pdf.Phishing.TtraffRobotInstall-7605656-0 further supports this, indicating a phishing or traffic redirection scheme. The document body is heavily obfuscated and does not provide clear textual lures.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://imaginedreaming.net/uploads/1/3/0/4/130435544/2763945.pdf In PDF document text
    • http://nmediadigital.com/uploads/1/3/0/5/130538866/nidodimepi-jajuje.pdfIn PDF document text
    • http://www.dancingravenstoneworks.com/uploads/1/3/0/6/130603866/feviboxopuf_xusitijel_nojizegafatap_didik.pdfIn PDF document text
    • http://cdaap.org/uploads/1/3/0/3/130324207/98262b13789f3ae.pdfIn PDF document text
    • http://hbo07.com/uploads/1/3/0/6/130604637/8069669.pdfIn PDF document text
    • http://lovewisdomfractal.com/uploads/1/3/0/5/130588749/bagofewulokudu.pdfIn PDF document text
    • http://p4partyproductions.com/uploads/1/3/0/5/130540928/notidamawafiku.pdfIn PDF document text
    • http://sheareigns.com/uploads/1/3/0/8/130814177/fc182d6bbe51.pdfIn PDF document text
    • http://alexpaterakis.com/uploads/1/3/0/6/130605519/rawifinobuv_supofugi_zabinuxadedeku.pdfIn PDF document text
    • http://accoladetechnoheights.com/uploads/1/3/0/5/130589354/3011017.pdfIn PDF document text
    • http://mta-sts.mail.zionchristianretreat.org/uploads/1/3/0/6/130604042/7b4ef8470c57.pdfIn PDF document text
    • http://reddiamondbenefits.com/uploads/1/3/0/8/130873978/rusatefafotiro.pdfIn PDF document text
    • http://www.andrewperry.org.uk/uploads/1/3/0/6/130603838/3542e.pdfIn PDF document text
    • http://spacecreationdesign.com/uploads/1/3/0/7/130775269/130775269.html#fiba+asia+newsIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f87.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2F87 8536 bytes
SHA-256: 2f3bec70c1b877075032ea4f6100c4a87801d5b5c90a36aa297f5f1ad6f0c69c