Malicious PDF — malware analysis report

Static analysis result for SHA-256 587ef981b874bbe5…

MALICIOUS

PDF

54.2 KB Authoring application: Nitro PDF
MD5: d5ab1c21b8c4c4a50f88647c6956525d SHA-1: 9518eb2ad67483fa6ced3006157e6fa0adc53fbd SHA-256: 587ef981b874bbe5af6d79ca69fbf0916c4f7747dca589a2a8ffc0c5d90b4a9f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files hosted on various domains. This behavior is indicative of a link farm or a distribution mechanism for further malicious content, as flagged by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV detection further support the malicious nature of this file. No scripts were extracted, and the document body content was heavily corrupted, making it impossible to determine a specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://movetoamendpdx.org/uploads/1/3/0/3/130313186/1344ec5b200d90.pdf
    • http://myitk.us/uploads/1/3/0/2/130273803/vomurapofinuso-bakifujibuxefon.pdf
    • http://cpanel.true-leaf.net/uploads/1/3/0/4/130489044/pozinegot_tilurejexunowel_kifabuxolizi_leviku.pdf
    • http://prelude-to-action.com/uploads/1/3/0/3/130323478/fatotew.pdf
    • http://prosisw.com/uploads/1/3/0/5/130550742/varajexafumivoz-derozubeni-pajilot-sesixaderusapes.pdf
    • http://www.ryanjameslandscapingri.com/uploads/1/3/0/8/130874564/4217797.pdf
    • http://jvwritingv2.club/uploads/1/3/0/8/130814143/c2a365e7f3e0400.pdf
    • http://aandshardwoodflooring.com/uploads/1/3/0/4/130476066/masijo-jodugegepug-jidisorusujor.pdf
    • http://waterstonecafe.com/uploads/1/3/0/7/130776755/rodazatifanetuzubas.pdf
    • http://capdisttutor.com/uploads/1/3/0/3/130313434/birelesawax.pdf
    • http://matthewgeller.net/uploads/1/3/0/5/130590059/mejip.pdf
    • http://lakeviewbuchanan.com/uploads/1/3/0/3/130323127/7614820.pdf
    • http://northolmesjuniorschool.com/uploads/1/3/0/6/130605036/tuxoxaresax.pdf
    • http://mail.demo.famhealth.com/uploads/1/3/0/5/130547112/9311119.pdf
    • http://angeliquedeclercq.be/uploads/1/3/0/4/130478106/dudasizemip.pdf
    • http://clarender.com/uploads/1/3/0/4/130476069/4419e.pdf
    • http://hoppipop.com/uploads/1/3/0/3/130313564/8c4741d5c5b9.pdf
    • http://www.sfhsgirlslax.com/uploads/1/3/0/2/130274343/6955498.pdf
    • http://bssdnp.salon225.com/uploads/1/3/0/6/130639294/130639294.html#how+to+convert+a+polar+equation+to+a+cartesian+equation

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004305.bin
44bc507e6feece4b5ec51d67d3f3322caae0b47fa6f13d11cd391cbfb070b514
pdf-font-stream PDF embedded font (sfnt) at offset 0x4305 6644 bytes
font_01_sfnt_off0000530a.bin
319f9c996375511bbe969d0b76506a2162f7d522988cd2631b41a5a1e417b94d
pdf-font-stream PDF embedded font (sfnt) at offset 0x530A 16040 bytes
font_02_sfnt_off00006731.bin
db056d6b75001de5db1a3468c5d064d74740f4b0d9fc0843f21179ce511eb003
pdf-font-stream PDF embedded font (sfnt) at offset 0x6731 2852 bytes
font_03_sfnt_off00007412.bin
7b96095765616586e967c6c2dec577b5d6056b072e23222df6ff027231d72286
pdf-font-stream PDF embedded font (sfnt) at offset 0x7412 8584 bytes