Malicious PDF — malware analysis report

Static analysis result for SHA-256 70cb9b1b1238e6a2…

MALICIOUS

PDF

40.3 KB Authoring application: Nitro PDF
MD5: 5b009066c4732faacb59b87dca2b86dc SHA-1: a0ff3768aadb0b3ffa73e423f8b6a29bcaca4347 SHA-256: 70cb9b1b1238e6a224791d90edd99fd67b6941eb72935d8192eb6cfca43d89c1
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO spam or to redirect users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as Pdf.Phishing.TtraffRobotInstall. The embedded URLs are the primary indicators of this malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://glammeshops.com/uploads/1/3/0/3/130379087/1009732.pdf
    • http://sose.thebestessay.info/uploads/2020/01/28/6955631.pdf
    • http://thehighlandshollywood.org/uploads/1/3/0/4/130483512/didise.pdf
    • http://newzineland.weebly.com/uploads/1/3/0/4/130435780/ddf3278c03f37af.pdf
    • http://ntcmembers.weebly.com/uploads/1/3/0/3/130324030/lozagawunowi-wilusimowum-ropopuwox-jalikawiki.pdf
    • http://wozi.insnet.ru/uploads/2020/01/27/4552713.pdf
    • http://gukej.photo-vologda.ru/uploads/2020/01/28/8b2eea0112c225a.pdf
    • http://fofozini.laritelle.info/uploads/2020/01/27/xedaz_tusilasami.pdf
    • http://lebanonvalleydc.com/uploads/1/3/0/6/130621938/fc89b91203fb8.pdf
    • http://thegoldenstateacademyschoolofspeechanddebate.com/uploads/1/3/0/2/130289262/pugukiriwuxi.pdf
    • http://fesa.kvoma.ru/uploads/2020/01/29/6093848.pdf
    • https://mabobewug.weebly.com/uploads/1/3/0/5/130543682/f62a58aab4645.pdf
    • http://xoxomaj.molleo.in/uploads/2020/01/28/doxafegodosivaxes.pdf
    • http://lulis.newstimes.ru/uploads/2020/01/28/8cb88b5e259.pdf
    • http://massagetresbelle.com/uploads/1/3/0/5/130588382/vemajelojutivona.pdf
    • https://pukifemeju.weebly.com/uploads/1/3/0/5/130589450/5005095.pdf
    • http://asociacionperiodistaspr.org/uploads/1/3/0/2/130272649/130272649.html#role+of+contrastive+analysis+in+language+teaching

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000014b2.bin
915401bf5ca066b88e045001911eba8f96b8ccfbbb7ecb925d43a921fabfe680
pdf-font-stream PDF embedded font (sfnt) at offset 0x14B2 8456 bytes