Malicious PDF — malware analysis report

Static analysis result for SHA-256 3fc462170e848712…

MALICIOUS

PDF

125.9 KB Authoring application: LibreOffice
MD5: 3ffadb152c14ae61f73a2b8e2ccb57d6 SHA-1: 5338ed1aebcbc76f9802c07d814b3025b3f93e78 SHA-256: 3fc462170e8487129321e6e6d8ae1f0370a9299a837bf01ecb4fc523fa7fea0a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to other PDF files hosted on various domains. This behavior is indicative of a link farm or a distribution mechanism for further malicious content, as suggested by the ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The document body itself appears to be malformed or contains obfuscated text, providing no clear user-facing lure.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://marine.rtfmanufacturing.com/uploads/1/3/0/7/130775346/663785.pdf
    • http://treasureoftheandes.com/uploads/1/3/0/2/130272505/voxewosakixejemu.pdf
    • http://honeypeelfarm.com/uploads/1/3/0/3/130323315/712626.pdf
    • http://wmvcopperart.com/uploads/1/3/0/7/130738554/942323189e229.pdf
    • http://ccf-ag.org/uploads/1/3/0/8/130814065/3968814.pdf
    • http://centerforcouplesandfamilies.com/uploads/1/3/0/6/130621106/1971008.pdf
    • http://gurkanagircan.com/uploads/1/3/0/4/130476339/dafb008.pdf
    • http://candeelandproductions.com/uploads/1/3/0/5/130539269/7108488.pdf
    • http://hopefulwellness.com/uploads/1/3/0/3/130313495/pejim-xilukinitatidag.pdf
    • http://jy-la.org/uploads/1/3/0/6/130604476/nozuxuxexi.pdf
    • http://filtrasi.com/uploads/1/3/0/5/130539497/jijeje.pdf
    • http://solutionslocker.com/uploads/1/3/0/6/130639199/gozifiru-jowir-nuduvejewife.pdf
    • http://richardramos.net/uploads/1/3/0/7/130776693/mufadurupulitivibija.pdf
    • http://webdisk.tavernandtap.com/uploads/1/3/0/8/130813967/patedamif.pdf
    • http://playforgood.com/uploads/1/3/0/4/130483204/tajelobo.pdf
    • http://ohigholifedesigns.shop/uploads/1/3/0/4/130483349/db687c.pdf
    • http://elmiloveyou.com/uploads/1/3/0/2/130272619/02a0d9766b6.pdf
    • http://realestatebuyersflorida.com/uploads/1/3/0/5/130589014/f0f1c.pdf
    • http://buckhillcoffee.com/uploads/1/3/0/2/130289359/ninowu.pdf
    • http://suefordedtechportfolio.com/uploads/1/3/0/5/130588622/pupisabatujixewobo.pdf
    • http://srguniversity.com/uploads/1/3/0/5/130539097/3788427.pdf
    • http://mta-sts.savschill.com/uploads/1/3/0/5/130546343/kotijon-bapegutami-keregewa.pdf
    • http://mpatoska.com/uploads/1/3/0/8/130814575/1bfa26eda.pdf
    • http://onpointmedicalrecruiting.com/uploads/1/3/0/7/130740110/mixerujin.pdf
    • http://2fey9h.salon225.com/uploads/1/3/0/3/130379370/130379370.html#hemoglobin+chemical+formula+structure
    • http://buckhillcoffee.com/uploads/1/3/0/2/13028935

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002b2e.bin
84631c6bcf81fa873b987714ed4cc776f328478c5b3cafe22d7a0c8d884c6f82
pdf-font-stream PDF embedded font (sfnt) at offset 0x2B2E 11188 bytes
font_01_sfnt_off00010a65.bin
ce07eb9461262d379961ad4920af677ca084d471c7b3b6870ad4f61acce85119
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A65 17036 bytes
font_02_sfnt_off000122ba.bin
9502fe3ffb58d1f9c0d3e9da8595af994e8ac7c05a1a1207bbd199826b97c4bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x122BA 4440 bytes