Malicious PDF — malware analysis report

Static analysis result for SHA-256 5349e8b0cf1128a7…

MALICIOUS

PDF

37.5 KB Authoring application: PDF Studio
MD5: 0e7c8be346eab94e8300deb7d6b616a0 SHA-1: effa972bc0e050bc9063b4dea76355dde5663aff SHA-256: 5349e8b0cf1128a711f33929cc54082ab8e993b4b5699773bb99355f2d3b149b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a large number of embedded links to other PDF files, a technique commonly used for SEO poisoning and phishing. The document body, though partially corrupted, suggests a lure related to safety data sheets. The ClamAV detection and ML classifier strongly indicate malicious intent, likely to redirect users to malicious content or download further malware. The primary IOCs are the numerous external URLs pointing to potentially compromised or malicious PDF hosting sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rockofagesbiblecamp.com/uploads/1/3/0/2/130274281/d1f8dcbf69.pdf
    • http://xorixoli.smartmeteo.ru/uploads/2020/01/28/pudolofifopuxevus.pdf
    • http://doloresgrillocoach.com/uploads/1/3/0/2/130288753/d95caa17fc5df.pdf
    • http://dorothyradio.com/uploads/1/3/0/5/130588980/wonawufotajore-gojuputafufori-ponote.pdf
    • http://newhopephotographylakeland.com/uploads/1/3/0/3/130379959/4036527.pdf
    • http://bigcreekkennels.com/uploads/1/3/0/6/130621020/6256553.pdf
    • http://lijikeb.pennystockpromotions.com/uploads/2020/01/28/gaminat.pdf
    • http://silviojimenez.com/uploads/1/3/0/6/130603865/339836.pdf
    • http://ecrirebeaute.com/uploads/1/3/0/6/130605435/4940645.pdf
    • http://soulography1111.com/uploads/1/3/0/6/130639129/rokuxorepun.pdf
    • http://misisavuj.rentkazan.com/uploads/2020/01/29/vavozutuwuge.pdf
    • http://doriboguna.limma-game.ru/uploads/2020/01/28/milolubo.pdf
    • http://disneychristmasparty.com/uploads/1/3/0/5/130542781/1400758.pdf
    • http://danielshanethomas.com/uploads/1/3/0/2/130272477/6432329.pdf
    • http://pianomethod.info/uploads/1/3/0/6/130605229/wilolefesemuvifex.pdf
    • http://mytexasautoholdings.com/uploads/1/3/0/5/130544954/zubitaze_papugil_ziwegadan.pdf
    • http://greensidecorp.com/uploads/1/3/0/4/130483748/xerud-wisanidevoxeje.pdf
    • http://zodus.excepcion.tech/uploads/2020/01/28/498365.pdf
    • http://kek.stat-roditelyami.ru/uploads/2020/01/28/lajug_zetomuzileb_xuvotunipal.pdf
    • http://mikkiscreations.shop/uploads/1/3/0/5/130589275/102808.pdf
    • http://mydietea.com/uploads/1/3/0/5/130588347/lijobamelezuroku.pdf
    • http://thelevelupshow.com/uploads/1/3/0/6/130620836/4948764.pdf
    • http://carpetcleancary.com/uploads/1/3/0/5/130543761/130543761.html#lysol+cleaner+safety+data+sheet
    • http://mydietea.com/uploads/1/3/0/5/1305883

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000163e.bin
187fe44c7557d92490d2b626a0f9e7aabfb470cfd3179c147ae7c5f4c5acff40
pdf-font-stream PDF embedded font (sfnt) at offset 0x163E 8284 bytes