Malicious PDF — malware analysis report

Static analysis result for SHA-256 47d715bd459f18e0…

MALICIOUS

PDF

65.6 KB Authoring application: Serif PagePlus
MD5: f5d12d54a30d3b982e1902878f7f8a02 SHA-1: ea09557ab132a516b45c7e79b67a634a1b5e85f0 SHA-256: 47d715bd459f18e0b71d1a45f87d393def7bcf268cf48f91fba04cb5e426f6e4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to other PDF files, a technique commonly used for SEO poisoning and distributing malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output strongly indicate malicious intent. The document body, though heavily obfuscated, contains references to 'datasheet' and microcontroller names, suggesting a lure to disguise the malicious link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9941

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://startingpoint.info/uploads/1/3/0/2/130272234/jajazex.pdf
    • http://excelappdevelopment.com/uploads/1/3/0/7/130775268/9cec63fb.pdf
    • http://clickpayservices.com/uploads/1/3/0/2/130289668/dukipiwibano.pdf
    • http://msjsport.net/uploads/1/3/0/6/130605044/3550788.pdf
    • http://dancinggoatsanctuary.com/uploads/1/3/0/7/130776015/130776015.html#lpc1768+cortex-+m3+datasheet

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012b1.bin
6a38d202f9465c26b3cddb706ff8f54dbd1c0eed919e24b210e5cb77e8e9a305
pdf-font-stream PDF embedded font (sfnt) at offset 0x12B1 11136 bytes
font_01_sfnt_off0000890e.bin
c9655644a945a2bc46672e4d4588f8b8f0381e8adfc868cce1c18b57f13076a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x890E 9744 bytes
font_02_sfnt_off00009d3a.bin
76d0edce5bdb93a691a0309c49e7369480f5d97eef5486ab960fc16df6d92a06
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D3A 16384 bytes
font_03_sfnt_off0000b32c.bin
3f0deae35548b73ccdda74359308afc4ecad6966c87c329a4fc742abc41f9ae0
pdf-font-stream PDF embedded font (sfnt) at offset 0xB32C 9252 bytes