Malicious PDF — malware analysis report

Static analysis result for SHA-256 56d15856f188d77f…

MALICIOUS

PDF

53.4 KB Authoring application: ImageMagick
MD5: c86c3d79ce6690261a96f7f8015f23dc SHA-1: ec12f08579a68341ad73a7465fe0239f6b7ba044 SHA-256: 56d15856f188d77f80091e4320a20ade0ce51d0cd5926316633b8562f65f776f
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file exhibits a critical heuristic firing for PDF_SEO_LINK_FARM, indicating it contains a large number of external PDF links. This is further supported by ClamAV detecting it as Pdf.Phishing.TtraffRobotInstall. The presence of numerous embedded URLs, all pointing to PDF files on various domains, strongly suggests a malicious intent to redirect users to potentially harmful content, likely for phishing or malware distribution. No scripts were extracted from this sample.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://witsendvineyard.com/uploads/1/3/0/8/130814066/vefeveru.pdf
    • http://geniuspath.ai/uploads/1/3/0/4/130476649/3149914.pdf
    • http://uxguys.mobi/uploads/1/3/0/4/130488626/9844681.pdf
    • http://t-vic.com/uploads/1/3/0/5/130539871/81469.pdf
    • http://dogsrulesj.com/uploads/1/3/0/7/130776516/f38c661ea160.pdf
    • http://opvakantienaaribiza.nl/uploads/1/3/0/3/130323407/589072.pdf
    • http://koolcompanies.com/uploads/1/3/0/6/130640063/fabapalipu-remite-xaduv-makon.pdf
    • http://mrlapta.com/uploads/1/3/0/2/130273790/6796979.pdf
    • http://amcarizona.com/uploads/1/3/0/7/130776304/9356854.pdf
    • http://unrivalledathletics.com/uploads/1/3/0/5/130551386/7887731.pdf
    • http://sixiememonde.info/uploads/1/3/0/5/130589145/c9781ebea4.pdf
    • http://car-gocarriers.com/uploads/1/3/0/2/130287976/64e42337d289.pdf
    • http://encyclobeerdia.com/uploads/1/3/0/6/130640090/8c0e7.pdf
    • http://bodybydrea.net/uploads/1/3/0/2/130272336/c150bda5d1.pdf
    • http://nadzorybudowlane-arles.pl/uploads/1/3/0/5/130588531/0884f701d1c7715.pdf
    • http://qnek.net/uploads/1/3/0/4/130489530/97d8f0d64976ebf.pdf
    • http://psalm128.com/uploads/1/3/0/2/130272619/tifavimewutezowoto.pdf
    • http://ivjournal.org/uploads/1/3/0/5/130541188/3aa203a909c7dd.pdf
    • http://mojiles.net/uploads/1/3/0/3/130324005/gagepepiboj.pdf
    • http://librodeestilo.org/uploads/1/3/0/7/130775928/5355c.pdf
    • http://jdwylieengineering.com/uploads/1/3/0/6/130604133/ad384cafedf.pdf
    • http://dr-pratt-emotional-mastery.com/uploads/1/3/0/7/130776113/49f9e0c7f723b82.pdf
    • http://suncitycenterhomes.com/uploads/1/3/0/4/130476266/xigav_zajirum.pdf
    • http://studioksandb.com/uploads/1/3/0/5/130539913/pavifira_wekodo.pdf
    • http://mydatadriven.com/uploads/1/3/0/4/130483200/dotatama_jodok_wadedosenurer_dekavurezoj.pdf
    • http://ddeventsinternational.gammaxiques.org/uploads/1/3/0/2/130270937/130270937.html#hadith+search-arabic+with+english+translation

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off000038c5.bin
039f63da4dc8f10dae151b658af5dc59f979a0e59e2a00a8d74a0d81c2725116
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x38C5 24904 bytes
font_01_sfnt_off000068d4.bin
e0a9ad9894871403798025ce42f2661e384fe923e8fbaffe9d6225ad9d0cf32d
pdf-font-stream PDF embedded font (sfnt) at offset 0x68D4 10688 bytes