Malicious PDF — malware analysis report

Static analysis result for SHA-256 40561f1bf157184c…

MALICIOUS

PDF

37.5 KB Authoring application: QPDF
MD5: 14f414ed08aab6952cb3a678ad4c8ef1 SHA-1: 5e8883ce4b59526aedeefdf00edeb249e3c8b13a SHA-256: 40561f1bf157184c6bd1fddc08690f6a5d7dfcd9b9c75295626b226aa569a143
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, a technique commonly used for SEO poisoning or to direct users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically related to phishing. The embedded URLs are the primary indicators of compromise, likely leading to further malware or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://castletraining.org/uploads/1/3/0/7/130776886/300d2cb3.pdf
    • http://aenderungschneiderei-musovic.com/uploads/1/3/0/5/130541744/2954883.pdf
    • http://mycdcfbc.com/uploads/1/3/0/4/130483757/67fce.pdf
    • http://forsheylaw.org/uploads/1/3/0/5/130590436/takawunoxeb_malawifaxemiku.pdf
    • http://purelightyogaschool.com/uploads/1/3/0/5/130590366/roxuw_xilekisezalusiw.pdf
    • http://annesketch.com/uploads/1/3/0/5/130546923/bulivo.pdf
    • http://sensitivoantonio.it/uploads/1/3/0/6/130603884/7706359.pdf
    • http://blackforestcampingandaccessories.com/uploads/1/3/0/5/130589088/jinape.pdf
    • http://concertsbythecreek.com/uploads/1/3/0/2/130272856/6385022.pdf
    • http://carollemonrealtors.com/uploads/1/3/0/5/130551526/vopewonipak.pdf
    • http://carpetcleancary.com/uploads/1/3/0/8/130814933/130814933.html#agile+project+management+scrum+step+by+step+with+examples

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000129f.bin
b3a4db109c4deea7859a9840388c8b07835d22292a977a5622aba66fac1cc71e
pdf-font-stream PDF embedded font (sfnt) at offset 0x129F 8104 bytes