Malicious PDF — malware analysis report

Static analysis result for SHA-256 45b52b6f657407d1…

MALICIOUS

PDF

88.8 KB Authoring application: Scribus
MD5: c6afe1d90e32099f885f1c16c295292b SHA-1: db7346b2bd4d6d17c829bbc81663a85974189c8c SHA-256: 45b52b6f657407d11d6015148bc2059c0c3b9c970a723c6dcefd3ca8bdcfc025
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0 and exhibits a critical heuristic for a PDF link farm containing 30 external links. The primary intent appears to be redirecting users to numerous potentially malicious PDF files hosted on various domains, likely for phishing or malware delivery. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wundrmediapro.com/uploads/1/3/0/5/130551023/fulimogisunub_bogek.pdf
    • http://nebak.ginecologialeon.com/uploads/2020/01/28/lasoru-kimixegil.pdf
    • http://nextivatrainingteam.com/uploads/1/3/0/4/130477252/d458c20b.pdf
    • http://lightisadrug.com/uploads/1/3/0/6/130621047/3819535.pdf
    • http://wssdar.com/uploads/1/3/0/5/130544591/6483614.pdf
    • http://2diamond.ru/uploads/2020/01/29/9978347.pdf
    • http://bdruken.weebly.com/uploads/1/3/0/3/130312974/buvujisanos_wolududig_pilolezeriweb.pdf
    • http://alcoholfreepregnancymn.com/uploads/1/3/0/6/130639960/xorurega.pdf
    • http://nccsecec.org/uploads/1/3/0/6/130603855/rukizatuvejapo_pibikevu.pdf
    • http://sunnydoggrooming.com/uploads/1/3/0/5/130543816/zawefakagusosone.pdf
    • http://my-closet-online.com/uploads/1/3/0/4/130488736/8825464.pdf
    • http://sunsteellogistics.com/uploads/1/3/0/6/130621100/3216380.pdf
    • http://kenmcknight.com/uploads/1/3/0/2/130287311/buzuluz-domuguk.pdf
    • http://redondoink.com/uploads/1/3/0/4/130476878/e7269.pdf
    • http://biking4life.org/uploads/1/3/0/5/130539702/gorolezixu.pdf
    • http://bejustalittlebetter.com/uploads/1/3/0/5/130551518/130551518.html#libro+american+english+file+1

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000687c.bin
b3c7893ddd320cfd5606f490a3363dabebf9a9e18f2f5e67f2209974e2cd0021
pdf-font-stream PDF embedded font (sfnt) at offset 0x687C 10184 bytes