Malicious PDF — malware analysis report

Static analysis result for SHA-256 41b2d1b6fee99863…

MALICIOUS

PDF

37.7 KB Authoring application: OpenOffice.org
MD5: a759e26702942fa0b6320353b5f56373 SHA-1: 844b07219f99d47da677f012d06fb8871442959d SHA-256: 41b2d1b6fee9986343f5d7611a88af5cbcfc319515be6ae644fb3e4a756c5f78
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links to external PDF documents hosted on various domains. This behavior is indicative of a link farm, often used for SEO manipulation or to distribute malicious payloads. The ClamAV detection and ML classifier further support its malicious nature. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pascorealestateblog.net/uploads/1/3/0/5/130551001/rexepugikiv.pdf
    • http://oidzo.net/uploads/1/3/0/6/130622095/8887745.pdf
    • http://melindaedwards.com/uploads/1/3/0/7/130740206/6016717.pdf
    • http://hawaiilimo808.com/uploads/1/3/0/8/130874329/dovorutumuli-saligojafe-juwijuzosumujag-feregijo.pdf
    • http://hoosierdaddio.com/uploads/1/3/0/2/130287799/c458baad1c3.pdf
    • http://threebrothersremodeling.net/uploads/1/3/0/5/130539992/gokorizuzisutip_donaduviturege_muzom.pdf
    • http://www.aureliamichaelvoiceover.com/uploads/1/3/0/2/130289601/fibokibokusuralowito.pdf
    • http://nationalbusinesseducationweek.com/uploads/1/3/0/7/130738979/sonukapewi.pdf
    • http://chatlabs.ai/uploads/1/3/0/7/130738644/felixaxegad-soziboxajo-wenumimetuw-ledawegowop.pdf
    • http://enewrites.com/uploads/1/3/0/6/130639542/2f9d6e71e346559.pdf
    • http://otcdl.brdge.org/uploads/1/3/0/3/130313564/130313564.html#fifa+world+cup+2018+today+scores
    • http://threebrothersremodeling.net/uploads/1/3/0/5/130539992/gokorizuzisutip_donaduviturege_muzom

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f5e.bin
f89c0e0946aa0d1e48aa5356a2d31bc24f5b96ca1f2cb84330b25817f6444d93
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F5E 2024 bytes
font_01_sfnt_off00003b90.bin
0f157fa8c5068aa2c4bba1e692fd00bfdf06edb5940a06ec2316000c46b03d82
pdf-font-stream PDF embedded font (sfnt) at offset 0x3B90 8268 bytes