Malicious PDF — malware analysis report

Static analysis result for SHA-256 666f3c8585c020b8…

MALICIOUS

PDF

82.1 KB Authoring application: LibreOffice
MD5: 01175bce0e802994e676b93b19dc218f SHA-1: e34a09aaff6337c87b12c6d84cbd604986d61d0b SHA-256: 666f3c8585c020b81fad3d3509e4d1e8aa464eb45a8ba7dad5a57335dc0b760b
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF file contains a large number of embedded external links to other PDF files hosted on various domains, as indicated by the PDF_SEO_LINK_FARM heuristic. This behavior is often associated with SEO spam or distributing malicious payloads. The ML classifier and ClamAV detection further support its malicious nature. The document body is heavily obfuscated and does not provide clear instructions, but the sheer volume of external links suggests a malicious intent to redirect users or host further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mx.buddcreek.org/uploads/1/3/0/7/130739793/d72322744aaeaea.pdf
    • http://womensselfdefenseftmyers.com/uploads/1/3/0/2/130288419/fafewajira.pdf
    • http://webdisk.justforyouphotography.ie/uploads/1/3/0/6/130605302/18df258b6cfcb.pdf
    • http://host67-131-77-199.static.ahcnm.org/uploads/1/3/0/7/130739495/rajoledigopusikak.pdf
    • http://southwestenterprisesllc2015.com/uploads/1/3/0/7/130775366/wipatur-mizogiriro.pdf
    • http://heliconmuse.com/uploads/1/3/0/2/130289315/jobadix.pdf
    • http://shop.allimagesonline.com/uploads/1/3/0/8/130874380/5514481.pdf
    • http://applepickndays.com/uploads/1/3/0/8/130814308/risudoxax.pdf
    • http://www.mountpleasantpark.com/uploads/1/3/0/3/130313702/ravasiw.pdf
    • http://equestriansuccessdiary.com/uploads/1/3/0/6/130604642/3571589.pdf
    • http://get-salesforce.com/uploads/1/3/0/3/130379158/lapenonumixemobe.pdf
    • http://www.design-md.org/uploads/1/3/0/4/130475965/6650781.pdf
    • http://besticandib.com/uploads/1/3/0/6/130620483/32293d5a.pdf
    • http://zephyrhome.com/uploads/1/3/0/5/130588195/130588195.html#latex+use+math+symbols+in+text
    • http://www.nhncorp.comhttp://www.sandoll.co.krCopyright
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005e99.bin
c55457474138e52362cd67d5c273a2b4bdcc82766fb4fa00b510f3a93c9e5f94
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E99 2560 bytes
font_01_sfnt_off000067fa.bin
49f4fd2d63e443e38cbaadadfe89735560d6e4e54aec4cdc965daff191465149
pdf-font-stream PDF embedded font (sfnt) at offset 0x67FA 6256 bytes
font_02_sfnt_off0000767b.bin
7bbe142efd2b8ef4d0962219fcdd93e763f5b83a6827f721f3a31c1cd044d2da
pdf-font-stream PDF embedded font (sfnt) at offset 0x767B 6128 bytes
font_03_sfnt_off00008b09.bin
b41374cfe09826bf26cd9ac70971c6d4013863ba8370ae31d24393cc280949f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B09 30832 bytes
font_04_sfnt_off0000c50a.bin
55744db63812034eacb3c2576ef67e721f121069af3d12ae1ec896ede582b8c8
pdf-font-stream PDF embedded font (sfnt) at offset 0xC50A 9772 bytes
font_05_sfnt_off0000e4d7.bin
513a2c7c7a24510180a2c4bfe33400e14056e8c345e6ad7de750bf8891f614c2
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4D7 9752 bytes