Malicious PDF — malware analysis report

Static analysis result for SHA-256 762c650db4d9a2c5…

MALICIOUS

PDF

74.4 KB Authoring application: Soda PDF
MD5: b6ae663b636add068fc7df463320355b SHA-1: d7dd301cd178d298b6da5cbea496390b6033e41c SHA-256: 762c650db4d9a2c5c0c2d3d13eb4fbfaea5e1ea9c8b0a0fdc5ae9cdba1a1309d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links to other PDF files hosted on various domains, indicating a link farm or redirection scheme. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine the exact lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://terrifictooltrackers.com/uploads/1/3/0/6/130605216/nufujokezowu.pdf
    • http://rekopyr.store/uploads/1/3/0/4/130436299/pupuzewitudevuvoj.pdf
    • http://m.kaltydesigns.com/uploads/1/3/0/4/130483286/fc25b5.pdf
    • http://eraji.net/uploads/1/3/0/2/130272240/4556237.pdf
    • http://thedevyngunshow.com/uploads/1/3/0/3/130313613/7ad2981.pdf
    • http://pressreleasetime.com/uploads/1/3/0/5/130546432/jerivuguwekexak.pdf
    • http://onitscore.com/uploads/1/3/0/7/130775232/xezilavinoniv.pdf
    • http://cookacousticalconsultants.com/uploads/1/3/0/4/130475980/mofabawoxudorez-xetezire-sesutid-tumoxu.pdf
    • http://mvsexcavation.com/uploads/1/3/0/7/130775055/tifatekigurivafar.pdf
    • http://yourprofessionalheadspace.com/uploads/1/3/0/4/130476065/ad8a5cf61db.pdf
    • http://nhfrea.org/uploads/1/3/0/7/130738635/megutob.pdf
    • http://bartbenson.com/uploads/1/3/0/3/130379422/kopewazek.pdf
    • http://sallykfrey.com/uploads/1/3/0/4/130488311/fec020c548e.pdf
    • http://blackfeministwitch.com/uploads/1/3/0/6/130621979/130621979.html#computer+notes+pdf+in+hindi

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008cc4.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CC4 1388 bytes
font_01_sfnt_off000097c7.bin
f17fdc9a07d37911298dedda5e57374eb019c79274ed74e2c73dcac0850294d2
pdf-font-stream PDF embedded font (sfnt) at offset 0x97C7 19348 bytes
font_02_sfnt_off0000cb4d.bin
ad5028594287e41109e357fcd4a2cc3c4d72abf6179de90e624129aa90907dd2
pdf-font-stream PDF embedded font (sfnt) at offset 0xCB4D 8392 bytes