Malicious PDF — malware analysis report

Static analysis result for SHA-256 67f80bbfc6ae3120…

MALICIOUS

PDF

65.9 KB Authoring application: Pdftk
MD5: 45b7a95964ef18fe7fa8085ca092b5a1 SHA-1: 99d75e5b2158b625e86e3335ee542da476e80002 SHA-256: 67f80bbfc6ae3120725f98d1caa40e3eb119be829f4210ab777c11151aad7dba
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. This technique is often used to manipulate search engine rankings or to redirect users to malicious websites. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution via the linked PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ashtangayogaantwerpen.com/uploads/1/3/0/4/130489431/jepam.pdf
    • http://kefaloniavilla4rent.com/uploads/1/3/0/5/130551164/a0a9c.pdf
    • http://lookinggoodaz.org/uploads/1/3/0/4/130476821/sefabawudowofekujer.pdf
    • http://migrationcelebration.com/uploads/1/3/0/6/130621305/resodukiwix_kisemuwozemomi_ketipobakag.pdf
    • http://mwri.co/uploads/1/3/0/5/130540609/sexaw_lunobetopun.pdf
    • http://hotelescumbreswb.devsite-1.com/uploads/1/3/0/9/130969710/ripoxevet.pdf
    • http://emilysawamura.com/uploads/1/3/0/4/130435755/nafiwusaduva_vixet_pemiz.pdf
    • http://leadershipcv.com/uploads/1/3/0/5/130589402/1128541.pdf
    • http://thehotelgroupllc.com/uploads/1/3/0/4/130476276/7379651.pdf
    • http://scentifyfragrances.com/uploads/1/3/0/7/130775951/liwofuvemenolirujozo.pdf
    • http://iseizedthemoment.com/uploads/1/3/0/7/130775405/cb8d2d1cfb.pdf
    • http://www.idveri.net/uploads/1/3/0/4/130483445/130483445.html#how+many+black+cards+do+you+have+to+have+to+win+cards+against+humanity
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013e0.bin
5f1462783644dcf130ab09ad22e7218260ecccb3977c8b0b176899f2973dee8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x13E0 10072 bytes
font_01_sfnt_off0000b356.bin
cb96a7c124f3f62ac1c48d72204de4dfb1728b13fbc23622db2ff328a0c76ce7
pdf-font-stream PDF embedded font (sfnt) at offset 0xB356 2832 bytes
font_02_sfnt_off0000bcb5.bin
e9da195eb347e98483c83aede151a01ad54009548380750582cd51f4052a73da
pdf-font-stream PDF embedded font (sfnt) at offset 0xBCB5 16072 bytes