Malicious PDF — malware analysis report

Static analysis result for SHA-256 751526497376f7be…

MALICIOUS

PDF

34.2 KB Authoring application: Karbon
MD5: aadb6b6946ce0112a366c2d72134781a SHA-1: 9c350d8da249de6c50256c50b1805f50e0996a39 SHA-256: 751526497376f7be33208f7f183a219a2694634e0360a39660ba79ec219c85ab
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm with 26 links, indicating a likely phishing or SEO manipulation scheme. ClamAV detected this file as Pdf.Phishing.TtraffRobotInstall-7605656-0, and an ML classifier also flagged it with high confidence. The embedded URLs are the primary IOCs, suggesting the document's purpose is to redirect users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hostmaster.supercleanqueens.com/uploads/1/3/0/6/130620614/natuzepisagix.pdf
    • http://cbcor.org/uploads/1/3/0/3/130379347/14a3f601f6.pdf
    • http://www.padpro.net/uploads/1/3/0/8/130813903/venopikasuxagol_fujibutaso_vajipotuvunu_jujivakuxuxipe.pdf
    • http://www.amandamarquezdance.com/uploads/1/3/0/5/130546237/67db180c.pdf
    • http://shapenv.com/uploads/1/3/0/6/130621506/9928441.pdf
    • http://atcdevelopment.ca/uploads/1/3/0/7/130739163/f30bfaeae2c4e.pdf
    • http://bassittdesigns.com/uploads/1/3/0/7/130776786/17a3a4b09de5e8.pdf
    • http://thebuttonprocess.com/uploads/1/3/0/6/130620172/4a4c432e.pdf
    • http://finearttattooing.com/uploads/1/3/0/7/130738700/lifogupizanowe-serevubi-votomenax.pdf
    • http://simplyramie.net/uploads/1/3/0/8/130873954/92014.pdf
    • http://bodytuningnmt.com/uploads/1/3/0/7/130776079/2f753409.pdf
    • http://collegejim.com/uploads/1/3/0/5/130541803/8849136.pdf
    • http://www.venezuelatruth.com/uploads/1/3/0/5/130588468/4188556.pdf
    • http://qhgk3.bpmtc.com/uploads/1/3/0/6/130621630/130621630.html#acog+preterm+steroids

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002bfc.bin
d1d2860e7f95d7150dfc2ce427be6dbc0db277913fbfe7be43b87ac0f5d7a187
pdf-font-stream PDF embedded font (sfnt) at offset 0x2BFC 8092 bytes