Malicious PDF — malware analysis report

Static analysis result for SHA-256 688afbef528ba902…

MALICIOUS

PDF

50.5 KB Authoring application: Serif PagePlus
MD5: cc9ce193c0962f554c78ba3c92d2c694 SHA-1: cb4b2adf00b4effba8f67a7aab41181a24a6067a SHA-256: 688afbef528ba9024fa46537126d2dde48c39d525182ab4b285c58336b7cca19
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a mass external link farm pointing to other PDFs, identified by the 'PDF_SEO_LINK_FARM' heuristic. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output strongly indicate malicious intent. The document body, despite being heavily obfuscated, suggests a lure related to a 'pay commission calculator' for teachers, combined with a call-to-action phrase, likely to trick users into downloading the linked malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://down-the-block.com/uploads/1/3/0/5/130551023/wakijuz.pdf
    • http://aialumassage.com/uploads/1/3/0/2/130289611/34aaed6ae.pdf
    • http://www.minimalteacher.com/uploads/1/3/0/5/130551920/c3d5430a53.pdf
    • http://my-zero-stress.com/uploads/1/3/0/6/130604162/pufisitif.pdf
    • http://enduringlovememorials.com/uploads/1/3/0/6/130621906/2750493.pdf
    • http://justgreatcareers.com/uploads/1/3/0/6/130621051/4358805.pdf
    • http://nakedroots1.com/uploads/1/3/0/5/130543369/nuwakujabapaw.pdf
    • http://maltaglasscreations.com/uploads/1/3/0/4/130477335/30c9a9f100e.pdf
    • http://artsestate.com.au/uploads/1/3/0/6/130605094/guvotuna.pdf
    • http://app5.online/uploads/1/3/0/2/130270813/lirodu.pdf
    • http://bakednbonedpdx.com/uploads/1/3/0/2/130289322/kuwozesusaxed.pdf
    • http://ihrtechservices.net/uploads/1/3/0/5/130589036/vonufamivigipeg_rujokuz_ramakoxadig.pdf
    • http://slumber.blog/uploads/1/3/0/7/130739520/fitoranogufeletutos.pdf
    • http://canopymgm.com/uploads/1/3/0/6/130604125/93e37c3610aa.pdf
    • http://www.visualjunkie.co/uploads/1/3/0/4/130436173/87cfc093.pdf
    • http://newcoursecompliance.com/uploads/1/3/0/5/130588627/4b162bccd1eae87.pdf
    • http://driedspicedapples.com/uploads/1/3/0/2/130291441/zexogowupuzi_tonerukiwakuti_kovutuwisusa.pdf
    • http://screencircus.com/uploads/1/3/0/5/130589180/bebarizapipafu-sezudugezesu-wudenuragitolog.pdf
    • http://godofsea.org/uploads/1/3/0/7/130739286/somibofodulego.pdf
    • http://taiyangchengyazhouxinyukoubeiruhe.f18.ebkf.org/uploads/1/3/0/2/130289669/nisuxagorekuw.pdf
    • http://margeauxsplace.net/uploads/1/3/0/4/130476866/polirukukow-xewuwo.pdf
    • http://battlebuilding.com/uploads/1/3/0/8/130815008/3823582.pdf
    • http://democrathollow.com/uploads/1/3/0/4/130483864/3698815.pdf
    • http://myeclecticyoga.com/uploads/1/3/0/7/130775732/timajizoxetisapolu.pdf
    • http://graysay.tech/uploads/1/3/0/6/130621865/detivit-jovitanipege.pdf
    • http://host10.carmichaelnl.com/uploads/1/3/0/3/130323506/130323506.html#wb+pay+commission+calculator
    • http://fedorahosted.org/lohit
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030fa.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x30FA 1388 bytes
font_01_sfnt_off000039ac.bin
1141f4b585f7c2395d0579cd17b35ed3829783ae54df35802d59f46a7f28d5bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x39AC 13356 bytes
font_02_sfnt_off0000607a.bin
e57fae0141bbe740e159b2cc7940f862b0d05b866f5d67109b5706ed6c41882d
pdf-font-stream PDF embedded font (sfnt) at offset 0x607A 8236 bytes