Malicious PDF — malware analysis report

Static analysis result for SHA-256 6bcf8f5004f46e9c…

MALICIOUS

PDF

46.9 KB Authoring application: Adobe PDF Library 9.0
MD5: 33ce89b8b9b737a121aaa4876094723b SHA-1: 30d1d68dc7492d15583033bf1370d0ec326e0f72 SHA-256: 6bcf8f5004f46e9cfbf29e40164d30877ff59ac16e592d5f93ac59aef4f091ad
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for a link farm, indicating it is designed to host numerous external links. The document body, despite being partially obfuscated, mentions 'Ascaris male and female classification' and includes embedded URLs that are likely part of this link farm. These URLs are suspected to lead to malicious content, aligning with a phishing or redirection attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rollnrock.com/uploads/1/3/0/3/130379741/1552875.pdf
    • http://theindoorhockeyleague.com/uploads/1/3/0/4/130488157/tudurebad.pdf
    • http://reachacademytoledo.com/uploads/1/3/0/6/130604056/pukirazaresokare.pdf
    • http://alexhowarthpt.com/uploads/1/3/0/4/130435544/130435544.html#ascaris+male+and+female+classification

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001025.bin
9f880992610980e80b10df33fc9ce9535fb0cd8de1a44d68425bbbccbe40d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1025 8928 bytes