Malicious PDF — malware analysis report

Static analysis result for SHA-256 57c30d5366520d18…

MALICIOUS

PDF

40.5 KB Authoring application: OpenOffice.org
MD5: 1599130aabed652cbaab6d19349452df SHA-1: 02825804490908163201c1ee5cce160a45b7f555 SHA-256: 57c30d5366520d18e6b5e37ae7dc58ff9314d15900f69cd4f99cac2b5e12336c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was identified as malicious by ML classifiers and ClamAV, specifically flagged as Pdf.Phishing.TtraffRobotInstall. The critical heuristic PDF_SEO_LINK_FARM indicates the document contains a large number of external links, with the primary domain being binovoxilejilud.weebly.com. This suggests the PDF's purpose is to redirect users to a multitude of other potentially malicious PDF files, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://binovoxilejilud.weebly.com/uploads/1/3/0/2/130287873/weruxedil_rexes_fogoped_sunekipinam.pdf
    • http://fallbrookorganictrail.com/uploads/1/3/0/5/130551772/9061282.pdf
    • http://u-l.tech/uploads/2020/01/29/5755387.pdf
    • http://rogivefaru.master-byta.ru/uploads/2020/01/28/18bf00f5.pdf
    • http://puz.blamecharlie.com/uploads/2020/01/29/zowuzeka.pdf
    • http://weddingproct.com/uploads/1/3/0/2/130272275/fazufulepaxumagom.pdf
    • http://sporttihetki.net/uploads/1/3/0/5/130538946/2672737.pdf
    • http://pilatesandyogawithsharon.com/uploads/1/3/0/4/130483592/xawotifuvemax-wepatogegu.pdf
    • http://sweetpeasdreamzzz.com/uploads/1/3/0/4/130436315/ca392f97b16aa.pdf
    • http://kekuni.slaveda.com/uploads/2020/01/27/vijumuxosukugob.pdf
    • http://remont-apple1.icu/uploads/2020/01/29/vomisokivenageposa.pdf
    • http://pinheadsquilting.info/uploads/1/3/0/3/130313624/deralijavekomipopo.pdf
    • https://bawobuzodalib.weebly.com/uploads/1/3/0/3/130379219/51d5e2fa818e.pdf
    • http://jezo.frmclinicsrussia.ru/uploads/2020/01/27/1d3e08f463b3b49.pdf
    • http://lebanonvalleydc.com/uploads/1/3/0/5/130544318/wuziro.pdf
    • http://petroleumconsultingservices.com/uploads/1/3/0/2/130289371/ea3affe4fd6.pdf
    • http://gomriz.com/uploads/1/3/0/6/130640091/130640091.html#center+tapped+full+wave+rectifier+project

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000014e8.bin
cad9275fc0799b59121f68f63fd18715aade460cc48dc263abd2800bb6fbf814
pdf-font-stream PDF embedded font (sfnt) at offset 0x14E8 7824 bytes
font_01_sfnt_off000061b3.bin
cb64d0bbf5bdda507f4172dc8e3b881cbc6e602eba9baaedaadaacdb7b98b952
pdf-font-stream PDF embedded font (sfnt) at offset 0x61B3 2916 bytes