Malicious PDF — malware analysis report

Static analysis result for SHA-256 632245779db16ca6…

MALICIOUS

PDF

42.2 KB Authoring application: LibreOffice
MD5: 3b5693af8000a8f221b33e5bad691460 SHA-1: 236f00ac67950edb25abd004575bb952c08802bb SHA-256: 632245779db16ca6ebc51106fe0a591a953d10fb61beea1abcd34d366d8efdec
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to other PDF files, indicating a link farm or redirection scheme. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution. No scripts were extracted, but the sheer volume of external links suggests a coordinated effort to direct users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://monsterotiqa.com/uploads/1/3/0/7/130738693/55b7ba657.pdf
    • http://cannaquencher.com/uploads/1/3/0/4/130492963/letazolidefozi_fofiliduduj_wugolupov.pdf
    • http://aplacetorest.org/uploads/1/3/0/5/130543148/5462058.pdf
    • http://proautocareers.com/uploads/1/3/0/7/130739147/darijoweg.pdf
    • http://rjtowing.org/uploads/1/3/0/6/130621422/jawujuvidixibatewem.pdf
    • http://hotgirlsofamerica.com/uploads/1/3/0/6/130639954/gapog.pdf
    • http://douillesachocs.com/uploads/1/3/0/3/130323220/608741.pdf
    • http://cpanel.flynndistribution.com/uploads/1/3/0/5/130589450/xuwebital_solukakodax_nitiv.pdf
    • http://risingskyweddings.com/uploads/1/3/0/5/130590122/jesoxosimagaj.pdf
    • http://besutobites.com/uploads/1/3/0/4/130435929/danesosefamoxu-zugudulilavo.pdf
    • http://hostmaster.planp.be/uploads/1/3/0/3/130313286/jaxerajajirivud.pdf
    • http://mobotflexi.com/uploads/1/3/0/3/130313274/d627064777531d.pdf
    • http://firstretrospective.com/uploads/1/3/0/4/130488338/b1bff3662.pdf
    • http://mercedesbenzconnection.com/uploads/1/3/0/3/130313196/d5c93409f.pdf
    • http://carmarelpaso.net/uploads/1/3/0/2/130272328/d9d9e69a5.pdf
    • http://mikedonovancoronado.com/uploads/1/3/0/5/130590375/jerag-lezolesu-gagamap.pdf
    • http://bearsvsbabiesgame.net/uploads/1/3/0/5/130590162/dutajobafunedem_xafugowesavig_rajeminavojexa_xuwuw.pdf
    • http://mike4congress.com/uploads/1/3/0/3/130313748/fedb6960b6d9.pdf
    • http://9lggiv.bdgct.com/uploads/1/3/0/5/130589057/130589057.html#como+se+clasifican+las+bacterias+aerobias+y+anaerobias

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004529.bin
25d8113852e29a62cf79bc5631666faf646d32e18249dc158aff1ba6e4db7033
pdf-font-stream PDF embedded font (sfnt) at offset 0x4529 9444 bytes