Malicious PDF — malware analysis report

Static analysis result for SHA-256 69fc199eacb97393…

MALICIOUS

PDF

37.0 KB Authoring application: Nitro PDF
MD5: 5c7bc71335f0f59bdd072109b68c87ef SHA-1: 8f621529beb139ca12da0e5406cef078565cb5d0 SHA-256: 69fc199eacb97393e17f836461d501826587d4ea155cf7a26f02ff7f257b65da
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious intent. The primary finding is a large number of embedded external links, suggesting a link farm or a distribution point for further malicious content. The document body is heavily obfuscated and does not provide clear instructions, but the presence of numerous URLs points towards a phishing or SEO manipulation attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cadencechiassonlmft.com/uploads/1/3/0/6/130605083/41662645e.pdf
    • http://curtissosa.com/uploads/1/3/0/4/130483302/3412991.pdf
    • http://petradesigns.net/uploads/1/3/0/5/130544494/2170564.pdf
    • http://bcsinmoohapkido.com/uploads/1/3/0/6/130621614/3d8aed.pdf
    • http://arcticethics.org/uploads/1/3/0/6/130604229/jesenemumunede.pdf
    • http://lifecoachhawaii.com/uploads/1/3/0/2/130271212/logirukatedab_mafemawepinuvi.pdf
    • http://qualitytransportservice.com/uploads/1/3/0/7/130775102/16a98a07c1.pdf
    • http://latercomics.com/uploads/1/3/0/6/130640063/levovibararuxefixew.pdf
    • http://nichellejensen4orem.com/uploads/1/3/0/6/130621022/wedopepunel.pdf
    • http://hostmaster.peaceful-minds.co.uk/uploads/1/3/0/3/130379141/a219ec0d6d264.pdf
    • http://snazzydiamonds.com/uploads/1/3/0/2/130270892/5057be1a25a74.pdf
    • http://brunchmemphis.com/uploads/1/3/0/8/130874269/28c39399.pdf
    • http://memsart-gallery.com/uploads/1/3/0/3/130313803/4715779d.pdf
    • http://pasadena-dogtraining.com/uploads/1/3/0/2/130291539/gewesumo-gebesej-vagutujozuf.pdf
    • http://pratnicka.com/uploads/1/3/0/7/130739144/37e5ba8.pdf
    • http://doorrush420.com/uploads/1/3/0/7/130740412/2527521.pdf
    • http://www.ericchampagneart.com/uploads/1/3/0/7/130775763/7900588.pdf
    • http://ersolutions.us/uploads/1/3/0/6/130620399/9529512.pdf
    • http://ferri-pesce.com/uploads/1/3/0/7/130775629/5676524.pdf
    • http://casparmckeever.com/uploads/1/3/0/3/130379158/ceb29b854.pdf
    • http://monetdiamondscollection.com/uploads/1/3/0/6/130604222/9549916.pdf
    • http://deannamcleod.com/uploads/1/3/0/6/130640239/685.pdf
    • http://officerethink.com/uploads/1/3/0/5/130545573/130545573.html#innervation+of+abdominal+muscles

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003014.bin
f68ca2f057af55ea2a7f811b74e4ef8eaf4876862f33780755bf8dc67b2c972d
pdf-font-stream PDF embedded font (sfnt) at offset 0x3014 7692 bytes