Malicious PDF — malware analysis report

Static analysis result for SHA-256 409a3045d91f0419…

MALICIOUS

PDF

39.1 KB Authoring application: GIMP
MD5: 3678359db8fc3520f395071f849b1009 SHA-1: 2bfd0aec472c1f27b3bda0e8fccc2706bfaf7b45 SHA-256: 409a3045d91f04196cee47d162f05b444eda528fc993457e94fbb0da71d15011
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. ClamAV identified this as Pdf.Phishing.TtraffRobotInstall-7605656-0, and an ML classifier also flagged it with high confidence. The document body mentions 'Azure information protection default labels' but is heavily obfuscated and contains numerous links, suggesting a lure or redirection mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vinubed.comunicazionequantistica.com/uploads/2020/01/28/xafed.pdf
    • http://magetointerieurbouw.com/uploads/1/3/0/6/130620197/wokejabewova.pdf
    • http://nhabatdongsan.com/uploads/1/3/0/6/130621979/dfb8ace3c74e613.pdf
    • http://drama-in-life.weebly.com/uploads/1/3/0/3/130323581/mixoniratawedi.pdf
    • http://tigateb.asolar.shop/uploads/2020/01/27/1d121e1c8a69c2b.pdf
    • http://jowujekija.agicole-acces.com/uploads/2020/01/27/tupirolulu.pdf
    • http://nhatrangpartytown.com/uploads/1/3/0/5/130589124/3843981.pdf
    • http://modajewelry.shop/uploads/1/3/0/5/130590395/5f4be33.pdf
    • http://asylumcollectables.com/uploads/1/3/0/5/130542996/70ba8907f.pdf
    • http://keki.onlycamp10.com/uploads/2020/01/29/7729938.pdf
    • http://bringmorehappy.com/uploads/1/3/0/6/130604878/130604878.html#azure+information+protection+default+labels

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001274.bin
657b2f3aee29d98fceef197f2d429d4f35dd53b75854b761ce0bf7ddc6205747
pdf-font-stream PDF embedded font (sfnt) at offset 0x1274 8328 bytes