Malicious PDF — malware analysis report

Static analysis result for SHA-256 734234adf906233f…

MALICIOUS

PDF

33.4 KB Authoring application: Solid Converter PDF
MD5: cd32cda9dba60fda80b6106cccd327f8 SHA-1: e2b07318f3c2d3858e6112ef25937b5ad1ecfb45 SHA-256: 734234adf906233f321f9ef69648b0ab4cf2f25d6e953070cda40b6dc0577985
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO poisoning or distributing malware. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. While no scripts were directly extracted, the embedded URLs are the primary indicators of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sophia-quest.com/uploads/1/3/0/5/130588288/8b61b3f68f.pdf
    • http://cpanel.kaitiakirestoration.co.nz/uploads/1/3/0/5/130551162/6899981.pdf
    • http://faltechbot.com/uploads/1/3/0/5/130588168/rulune_benuvixifot_dawubilomitazu.pdf
    • http://10xoceansolutions.com/uploads/1/3/0/8/130814984/41071c348e950a.pdf
    • http://cosylakedistrictcottages.co.uk/uploads/1/3/0/8/130874282/5081553.pdf
    • http://happyhorsehollow.com/uploads/1/3/0/6/130604685/tiraxitelip-lakujudowovofi-wagun.pdf
    • http://perumarket.net/uploads/1/3/0/5/130551155/adc8cdc.pdf
    • http://storeculdesac.com/uploads/1/3/0/6/130622033/579ed1.pdf
    • http://michaelnsmithsuperintendent.com/uploads/1/3/0/5/130539319/peladiwolawaka.pdf
    • http://www.rubbntugg.com/uploads/1/3/0/4/130489725/sudupudevodepi_genel.pdf
    • http://bshk.hklss.hk/uploads/1/3/0/2/130271184/8331672.pdf
    • http://host14.carmichaelnl.com/uploads/1/3/0/6/130603764/130603764.html#pluralisme+politique+exemple

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ba4.bin
acbe72d7b03e2fea196c12699ba9ca7985366ee4b4e92dbe6ab84eec966e5d72
pdf-font-stream PDF embedded font (sfnt) at offset 0x2BA4 8584 bytes