Malicious PDF — malware analysis report

Static analysis result for SHA-256 557b0ccc7b9e0ef8…

MALICIOUS

PDF

37.2 KB Authoring application: PDFedit
MD5: 3cf82b2f317d042f2f0b345166bd4ec5 SHA-1: 5a968a2865ea6fea6135ee958a534733fd048453 SHA-256: 557b0ccc7b9e0ef8c7d5500b71674d0ed01c72aeb7fca356358537557f1ea536
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, a technique commonly used to redirect users to malicious websites or download further malware. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall' further supports this assessment. The document body's content appears to be garbled or irrelevant, suggesting it's not intended for user interaction but rather as a container for the malicious links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://takeabowkilmarnock.com/uploads/1/3/0/7/130740141/rajetodakixevuwi.pdf
    • http://newresume2019.com/uploads/1/3/0/6/130621352/d36c1ff7c45e.pdf
    • http://rimavop.store/uploads/1/3/0/5/130588426/nexanumesuru.pdf
    • http://timelessfinds.net/uploads/1/3/0/6/130620778/9e44bb7013.pdf
    • http://meditono.com/uploads/1/3/0/8/130814104/2549186.pdf
    • http://psyneways.com/uploads/1/3/0/6/130639685/lugipavojelino.pdf
    • http://www.boodwah.net/uploads/1/3/0/6/130605373/nitus_nozejogibiwojem.pdf
    • http://swag-walk.com/uploads/1/3/0/2/130287289/7176895.pdf
    • http://aprilbaskin.com/uploads/1/3/0/6/130620584/retobufugamog.pdf
    • http://orbitvetmap.net/uploads/1/3/0/6/130639023/681798.pdf
    • http://bufalo-verbena.com/uploads/1/3/0/7/130776182/9176078.pdf
    • http://countrymusicpromo.com/uploads/1/3/0/6/130640182/75a0e8.pdf
    • http://host2.sbrsd.org/uploads/1/3/0/7/130775027/d569ea04a5d7963.pdf
    • http://247cardetailing.com/uploads/1/3/0/4/130483067/disiw.pdf
    • http://pollyshulman.net/uploads/1/3/0/5/130543941/0a6beaaa9.pdf
    • http://rebeccahoulden.com/uploads/1/3/0/6/130621447/4c3028f34.pdf
    • http://mkbrooks.net/uploads/1/3/0/8/130814297/rumidafadelepapinak.pdf
    • http://laparc.co.za/uploads/1/3/0/8/130873786/rudibif.pdf
    • http://sweetsadiesdoggieboutiqueonline.com/uploads/1/3/0/2/130287463/798817.pdf
    • http://newwomanrebel.com/uploads/1/3/0/2/130289551/1405928.pdf
    • http://desvosges.com/uploads/1/3/0/5/130545932/diganivuf.pdf
    • http://wondertraveltours.xsideas.com/uploads/1/3/0/7/130739934/130739934.html#citric+acid+anhydrous+merck+coa
    • http://orbitvetmap.net/uploads/1/3/0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ed1.bin
4e65f28d35d0fc7b25da9815c577674c99cd9269ba95cb4d4c913cf5f268fd03
pdf-font-stream PDF embedded font (sfnt) at offset 0x2ED1 8796 bytes