Malicious PDF — malware analysis report

Static analysis result for SHA-256 40ad4cc6411d8b5f…

MALICIOUS

PDF

62.4 KB Authoring application: OpenOffice.org
MD5: 614336d123e24f524172e525ba2a643e SHA-1: c26397deefd4b1ce9d2eeefe0e265617ea027eed SHA-256: 40ad4cc6411d8b5fb467fe3593079ec367f224e0636302a762eaf4cf146fec2d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection of 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further suggests a malicious intent, likely related to phishing or traffic redirection. The document body contains garbled text and embedded URLs, reinforcing the idea that the document's primary purpose is to host these links rather than convey meaningful information.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://imagingplanet.com/uploads/1/3/0/6/130604521/virubopevevoruf-gupepapamewure-fepulemezapu.pdf
    • http://kijuta.espace-clientsv3-0range.com/uploads/2020/01/29/7c10aa56f242.pdf
    • http://obogrevay.com/uploads/2020/01/27/5f3155.pdf
    • http://alliedpracticemanagement.com/uploads/1/3/0/3/130313673/pavewiwoke.pdf
    • https://kumuguxaset.weebly.com/uploads/1/3/0/4/130490078/kapikezegi.pdf
    • http://pemeren.sonamgusau.online/uploads/2020/01/27/xafusasop.pdf
    • http://finekykt.ru/uploads/2020/01/27/9245644.pdf
    • https://givivedal.weebly.com/uploads/1/3/0/5/130588221/e21cb28b.pdf
    • http://adancerstouch.com/uploads/1/3/0/6/130621460/todopatepa.pdf
    • http://gura.zagruzka7km.com/uploads/2020/01/29/8875504.pdf
    • http://maxiru.userboxes.ru/uploads/2020/01/27/3837ab.pdf
    • http://mibakaf.mindcraftstudio.com/uploads/2020/01/27/2ebd8.pdf
    • https://sizawaxu.weebly.com/uploads/1/3/0/5/130550805/mesosunoxezalu-jewidagigeli.pdf
    • http://barryboycephotos.com/uploads/1/3/0/3/130379342/9304454.pdf
    • https://rulowifapovik.weebly.com/uploads/1/3/0/6/130604512/1186859.pdf
    • https://banugazezabikeg.weebly.com/uploads/1/3/0/5/130551981/powokizugip.pdf
    • http://abundantlifecog.net/uploads/1/3/0/5/130551416/tewora.pdf
    • http://krediteka.ru/uploads/2020/01/27/574d125bc917.pdf
    • http://fegefuj.mtras.ru/uploads/2020/01/27/sonejipaxi.pdf
    • https://lamixesapovaba.weebly.com/uploads/1/3/0/4/130488732/8959971.pdf
    • http://natheia.com/uploads/2020/01/28/2212887.pdf
    • http://zimokajeke.planbani.ru/uploads/2020/01/28/7626852.pdf
    • http://pel.rstuff.xyz/uploads/2020/01/28/jigazujorogenu.pdf
    • https://rimatujenajo.weebly.com/uploads/1/3/0/6/130604933/7076429.pdf
    • http://stjohnvianneymorisset.com/uploads/1/3/0/4/130483041/130483041.html#terraria+fallen+starfish
    • http://fegefuj.mtras.ru/uploads/2020/01/27/sonejipaxi.pd

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000168b.bin
66f58b083458bf3f8876bea636310832e2691d59e007f01b7abdfffc267f21b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x168B 7968 bytes
font_01_sfnt_off00006a1a.bin
6db4bad143aab07e26f663993765340297adb9ba374df191914c9f0a1f933c29
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A1A 22228 bytes
font_02_sfnt_off0000ad8c.bin
6db2f878e0fd57d3a351d0d81a5ccd7b58f68df6728dadc3aee3ebeb1a1d6e60
pdf-font-stream PDF embedded font (sfnt) at offset 0xAD8C 16068 bytes