Malicious PDF — malware analysis report

Static analysis result for SHA-256 4d00691d1b4b269a…

MALICIOUS

PDF

40.8 KB Authoring application: Nitro PDF
MD5: 05726163c22d2b165cbdb7a803996b3f SHA-1: 97c95bac61fe85865dd08c504f692efc4ebb9cad SHA-256: 4d00691d1b4b269a01ccaa7087f64e2c148d71cdb37970353fa1e54ce30d57e9
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to other PDF files hosted on various domains, indicative of a link farm. This technique is often used to distribute malware or facilitate phishing attacks. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution via these links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://percorsidarte.com/uploads/1/3/0/2/130291441/5362587.pdf
    • http://buckbucklestein.com/uploads/1/3/0/6/130639273/8898195.pdf
    • http://worldofcoffee-dublin.com/uploads/1/3/0/6/130604949/ea7444.pdf
    • http://crimsonshadowpack.com/uploads/1/3/0/6/130621392/gofunoxovulaba.pdf
    • http://juneaudining.com/uploads/1/3/0/7/130775897/8354ae464a75791.pdf
    • http://friend-vibes.com/uploads/1/3/0/2/130289748/tavefebukiwi_vatikasipeg_pubuzajugulabe_sogatisenoru.pdf
    • http://discoverhomestores.com/uploads/1/3/0/6/130621163/valiwir_gonebufiduwipir_febirasole.pdf
    • http://northwestfineartstudio.com/uploads/1/3/0/3/130323835/e04f6b33add.pdf
    • http://stdesignmatters.com/uploads/1/3/0/7/130740166/6735614.pdf
    • http://mjyoga.net/uploads/1/3/0/4/130476427/waxevegezinuxa_nawujab_bedox_mufupe.pdf
    • http://matterportservices.com/uploads/1/3/0/4/130435509/9ef5995ca.pdf
    • http://dancinggoatsanctuary.com/uploads/1/3/0/7/130739980/130739980.html#can+i+convert+pdf+to+word+in+adobe+reader

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000133b.bin
9db2aa8c92878c0e4ecac805c30f0e8dd0b4031cc21f396966bc32a6164f0622
pdf-font-stream PDF embedded font (sfnt) at offset 0x133B 8036 bytes
font_01_sfnt_off0000584e.bin
f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
pdf-font-stream PDF embedded font (sfnt) at offset 0x584E 16204 bytes