Malicious PDF — malware analysis report

Static analysis result for SHA-256 734351b0771fe3a9…

MALICIOUS

PDF

49.1 KB Authoring application: Pdftk
MD5: 5f1b04763437058969b251c6bb5b609e SHA-1: 2555e08d35bebcf1293fa902ace8c88fe1945d6e SHA-256: 734351b0771fe3a986ec72aac2bf44151bea7f96b5f3da25239d169264670b6e
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded links to external PDF files, identified as a link farm. The document body, though heavily obfuscated, appears to be a lure related to a user manual. The presence of numerous external links suggests an attempt to redirect users to malicious content, potentially for phishing or malware distribution. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dcepool.net/uploads/1/3/0/7/130776067/lojopilosarizik.pdf
    • http://miohbeautiesofparadise.com/uploads/1/3/1/0/131069806/ninuwux-xazemok-mogipekepubogit.pdf
    • http://reallombardo.com/uploads/1/3/1/0/131070983/60758edb.pdf
    • http://quantuminstruments.com/uploads/1/3/0/6/130605405/guxelagadusekanufur.pdf
    • http://mta-sts.mx.interstatevapor.com/uploads/1/3/0/5/130589246/betel.pdf
    • http://striveaustralia.org/uploads/1/3/0/8/130813829/vaxasovimu-geburonolibi.pdf
    • http://nancynjuguna.com/uploads/1/3/0/3/130379232/2677a4c139.pdf
    • http://mta-sts.mail.createdforhope.org/uploads/1/3/0/4/130493893/82f42e198f2b4.pdf
    • http://www.darikalorello.com/uploads/1/3/0/6/130621179/5698740.pdf
    • http://akvapark.site/uploads/1/3/0/4/130489358/bujudif_livederewomoka_kimebafoz_makikazuwaven.pdf
    • http://www.noblestcapital.com/uploads/1/3/0/9/130969851/aa67c61985cef.pdf
    • http://cfg-ecommerce.com/uploads/1/3/0/6/130604406/6398001.pdf
    • http://fryingpanfoodadventures.com/uploads/1/3/0/4/130489431/xusubutaximirun-nejadawe-rufukitogopima-fekilubofapa.pdf
    • http://alexiszotos.com/uploads/1/3/0/6/130621185/lirewibafaki_nakok.pdf
    • http://www.alighahremaninezhadmiami.com/uploads/1/3/0/5/130545895/dupunujij.pdf
    • http://carrielcopeland.com/uploads/1/3/0/5/130539218/44ba4baebb6addd.pdf
    • http://angelschic.com/uploads/1/3/0/8/130874478/vanar_gajokakogo.pdf
    • http://www.beerfestwestchester.com/uploads/1/3/0/9/130969685/9053548.pdf
    • http://jethachan.com/uploads/1/3/0/6/130620964/kabuverer.pdf
    • http://4dainc.com/uploads/1/3/0/2/130271073/ronipokotot-kuxipijoponunuf-getisos.pdf
    • http://canterburypacific.com/uploads/1/3/0/7/130740210/5b6a97668c5.pdf
    • http://www.tavijuarez.com/uploads/1/3/0/7/130775735/metujaxesitob_midedugin_tosepepulo.pdf
    • http://boutiquemonmaitreetmoi.com/uploads/1/3/0/5/130539981/kinulub_katamafur_nelerowobededa_ledodur.pdf
    • http://74-123-77-219.mgwnet.com/uploads/1/3/0/3/130312929/29f9e654.pdf
    • http://mrsyatesclass.com/uploads/1/3/0/3/130323139/0b49e6599.pdf
    • http://www.thenannysden.com/uploads/1/3/0/7/130738831/130738831.html#delonghi+dolce+gusto+jovia+user+manual
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003c53.bin
966f45cd96030042f8b520c092a8b0723417dbc07720fa044f4e1fe3611b772f
pdf-font-stream PDF embedded font (sfnt) at offset 0x3C53 17160 bytes
font_01_sfnt_off0000586d.bin
f982a3b9ef2701c0716b17ebad20f95e3f2ab7f48a7822d6cb2794e62686d207
pdf-font-stream PDF embedded font (sfnt) at offset 0x586D 10084 bytes