Malicious PDF — malware analysis report

Static analysis result for SHA-256 7876543258de5440…

MALICIOUS

PDF

40.1 KB Authoring application: Solid Converter PDF
MD5: 39639da6d152c33f768245050ccb83ac SHA-1: c9e942c5d30188056040be0ac8ae950fed4fa7c5 SHA-256: 7876543258de54407095515490b386b1a56760ec439ed2ebf8cee8a06e1e115f
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF document contains a mass external link farm, with 24 links pointing to various PDF files hosted on different domains. This technique is often used for SEO manipulation or to distribute further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, and the embedded URLs suggest a mechanism for delivering secondary payloads or redirecting users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://harlemdata.com/uploads/1/3/0/2/130288410/zibajok_zobevos_zalefewivapal.pdf
    • http://reactasonellc.com/uploads/1/3/0/3/130323968/mutik-xevagidezubi-podofo-rupobesab.pdf
    • http://4bcenter.com/uploads/1/3/0/7/130739419/752110.pdf
    • http://www.fortagape.org/uploads/1/3/0/4/130476691/4905867.pdf
    • http://petsdr.net/uploads/1/3/0/3/130323151/jisezefad-lomazuguli.pdf
    • http://orlandolisted.com/uploads/1/3/0/8/130813497/4425390.pdf
    • http://fiatbroker.com/uploads/1/3/0/6/130640136/siboduxowixatilerid.pdf
    • http://www.samanderson.me/uploads/1/3/0/4/130489038/sibolozarojexu.pdf
    • http://mrsbhatt.com/uploads/1/3/0/5/130589186/6146257.pdf
    • http://mangaandanime.net/uploads/1/3/0/6/130605280/kalogetifon_vubewewapufa_sukadugoj_xedevumo.pdf
    • http://drizzlehealthy.com/uploads/1/3/0/7/130738620/7120531.pdf
    • http://cameraax.com/uploads/1/3/0/7/130775103/5652133.pdf
    • http://visionlinkshotelapartments3.devsite-1.com/uploads/1/3/0/6/130605229/130605229.html#un+mundo+feliz+aldous+huxley+ensayo
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000039a8.bin
d907c570f1f8f2d62f38d7529dbf77de46ca3a1917ec53aca7a78bae59874b04
pdf-font-stream PDF embedded font (sfnt) at offset 0x39A8 2616 bytes
font_01_sfnt_off00004558.bin
4291c845060ab638cab8375a9bc0a8eff823e238c56ba8a18c79bf4c90fab19e
pdf-font-stream PDF embedded font (sfnt) at offset 0x4558 8268 bytes