Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ed5fc2c984a8591…

MALICIOUS

PDF

44.7 KB Authoring application: QPDF
MD5: 1dca901fad5109275612b62f1f204a33 SHA-1: 9c117c8fc1f9396582163b2182c5436c1b977699 SHA-256: 4ed5fc2c984a8591295e3f6d7fd5eefb632fa7c59979f392e27438c8f853fd04
160 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains a large number of external links, characteristic of a SEO link farm, and is detected by ClamAV as Pdf.Phishing.TtraffRobotInstall. The document body suggests a social-engineering lure, instructing the user to install a browser extension or update to view content. This indicates the primary goal is to trick the user into executing malicious code or downloading further malware. The embedded URLs likely serve as landing pages for this lure.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://raxami.moscowhome-realty.ru/uploads/2020/01/28/rijojepizari.pdf
    • http://clear-home-solutions.com/uploads/1/3/0/6/130621581/vuwolizenizoruv_sokamenif_fomegitezowaxi.pdf
    • http://donilegend.com/uploads/1/3/0/5/130543084/lixug-govujefezuz-radan.pdf
    • http://cestagift.com/uploads/1/3/0/3/130379311/xejerizetigasaz.pdf
    • http://nourishmentinmotion.com/uploads/1/3/0/5/130590777/xifipigo.pdf
    • http://ssunitedstatesreef.com/uploads/1/3/0/6/130621642/02ef1d74331a0.pdf
    • http://mmtaxandfinancial.com/uploads/1/3/0/4/130476814/vigopajabewedibus.pdf
    • http://myidahoinsure.com/uploads/1/3/0/4/130477613/d1dc69f1ed0b4.pdf
    • http://nashobavalleyextractco.com/uploads/1/3/0/6/130639413/130639413.html#grid+template+repeat+auto

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001215.bin
6ab3459b13e8392058fead0036d954d1422b0997540171e6ede65fd6afd349a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x1215 8608 bytes
font_01_sfnt_off00006ac6.bin
3c2e106de6cb787409ee9e7a468dbada390938761ac748b466265f884e05639f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AC6 1960 bytes
font_02_sfnt_off000073c3.bin
1b3f82cd74c5b6671cc0c0d4a6c7877b74bb57ca469b2a61ef541918e41af838
pdf-font-stream PDF embedded font (sfnt) at offset 0x73C3 2652 bytes