Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ca09705dd8b24f3…

MALICIOUS

PDF

47.5 KB Authoring application: Poppler-utils
MD5: 2d37f3278adaca8b8f86885f46141926 SHA-1: 772c67196a7fe7db259360cd23646c2313fc3bb7 SHA-256: 3ca09705dd8b24f3621f40b6c3405152ed8353bcde870f0a35e004be9d382801
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a mass external link farm with 31 embedded URLs, indicating a phishing or malware distribution attempt. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports this assessment. The document body is largely unreadable, but the presence of numerous links suggests the primary malicious function is to redirect users to external, potentially harmful, content.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sozapakixu.gkmosolov.ru/uploads/2020/01/29/7484edb9ba744c.pdf
    • http://taze.oftathechers.com/uploads/2020/01/27/3488274.pdf
    • https://zinemegid.weebly.com/uploads/1/3/0/4/130477074/925234.pdf
    • http://fivam.remont-turbin-orenburg.ru/uploads/2020/01/29/2241962.pdf
    • http://salecheb.ru/uploads/2020/01/28/porivesetotala_wepazisefivaja_pejawewifezag.pdf
    • http://skyviewbands.weebly.com/uploads/1/3/0/6/130604879/wakofifidafivezi.pdf
    • http://norecordsnobs.com/uploads/1/3/0/6/130604885/sexug.pdf
    • http://cedarviewbaptist.org/uploads/1/3/0/6/130620207/xulofajeligeni.pdf
    • http://vasufega.sk-evrodom.icu/uploads/2020/01/28/lategetesil.pdf
    • http://shoppivotalchocolates.com/uploads/1/3/0/3/130313064/8460741.pdf
    • https://mefuwaviwakal.weebly.com/uploads/1/3/0/5/130544147/mudomanagavujoreje.pdf
    • http://cb15.org/uploads/1/3/0/2/130271177/7722384.pdf
    • http://rachaelcrevier.com/uploads/1/3/0/5/130544070/d41d7.pdf
    • http://gegexeb.rostelekomu.fun/uploads/2020/01/29/ae858754aef9e.pdf
    • http://oneactioncalendar.org/uploads/1/3/0/2/130287302/feposis.pdf
    • http://deadguycottoncandy.com/uploads/1/3/0/5/130589103/5303470.pdf
    • http://uwkfk.com/uploads/1/3/0/4/130483959/fazifigages.pdf
    • http://rinawe.kraftstone.ru/uploads/2020/01/27/5682250.pdf
    • http://designdancestudio.com/uploads/1/3/0/5/130590689/sijokinidawo.pdf
    • http://jussom.xyz/uploads/2020/01/27/xizir.pdf
    • http://kenesenebi.app3pinfo.online/uploads/2020/01/28/wexolorowu_xufamavujigeg_jumaze_guber.pdf
    • http://mid.aquacity67.ru/uploads/2020/01/27/logemisalibiwi.pdf
    • http://wasseem.cloud/uploads/2020/01/28/88561933e7dbaf.pdf
    • http://tillbase.net/uploads/1/3/0/2/130272804/lemesuzu-pazigilokaxi-gijorine.pdf
    • http://juliarogershamrick-art.com/uploads/1/3/0/5/130588858/xoputen_bebabemuraxi.pdf
    • http://shutouttraining.com/uploads/1/3/0/4/130476786/130476786.html#home+budget+spreadsheet+example

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001910.bin
e6eed4deacbfffda4bf43dad30669b07e3777a7f467176efb43cf88a0f526930
pdf-font-stream PDF embedded font (sfnt) at offset 0x1910 8476 bytes
font_01_sfnt_off00007154.bin
1d1fa5121415f8f5353993473374918b9d2a38f433752094af4cce5d3be72c8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7154 16312 bytes