Malicious PDF — malware analysis report

Static analysis result for SHA-256 7905167ffc1a8e9c…

MALICIOUS

PDF

37.8 KB Authoring application: Karbon
MD5: d0edfbbdad21c39f9a1fa1e57c9ab2fd SHA-1: 28fc55dcf64d57e9a503bb89410c1ddf6dd35764 SHA-256: 7905167ffc1a8e9ca30171b906dbe7e08eb4810fee7c2a0bcb97646ab951b213
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of embedded URLs pointing to external PDF files hosted on various domains, indicating a link farm or redirection scheme. The document body content is heavily corrupted and unreadable, but the presence of numerous external links suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://camptishomingo.org/uploads/1/3/0/6/130639972/c4d6c605cc82716.pdf
    • http://oldnewborrowed.com/uploads/1/3/0/2/130291449/5952748.pdf
    • http://cladnh.com/uploads/1/3/0/7/130739695/jobanefapu_nisabadovadi_dirinenoj.pdf
    • http://chuyitos.com/uploads/1/3/0/7/130776149/2e5ffeb82a.pdf
    • http://mx.joshdollison.com/uploads/1/3/0/6/130604532/jobowafudodel_jejikokogakaniz_kuwaxeri.pdf
    • http://one21i.com/uploads/1/3/0/6/130604222/daritesatulijufok.pdf
    • http://getfantasticmarijuana.com/uploads/1/3/0/7/130776542/vajotomezeje_jovasape_lituzawalezekav_fesewozenufofot.pdf
    • http://ericamcquiddypsyd.com/uploads/1/3/0/6/130605059/xosimusuwevo.pdf
    • http://3coconut.com/uploads/1/3/0/6/130620838/b64451aa7b1360.pdf
    • http://www.ejaznadeem.com/uploads/1/3/0/6/130621480/kenobafi-kiwal.pdf
    • http://mail.frankydoyle.com/uploads/1/3/0/6/130604779/3ca40b5.pdf
    • http://trinitykalispell.com/uploads/1/3/0/5/130540402/8460530.pdf
    • http://www.dejligedayswelcome.com/uploads/1/3/0/5/130589313/591290e7901cc.pdf
    • http://mycmatro.com/uploads/1/3/0/6/130622011/lutasu.pdf
    • http://ethergate.com/uploads/1/3/0/7/130739690/manasil.pdf
    • http://julfcave.net/uploads/1/3/0/6/130640059/gupalisexijesiti.pdf
    • http://worldwidegreatescapes.com.au/uploads/1/3/0/6/130604292/8612606.pdf
    • http://hopecenterhampton.com/uploads/1/3/0/4/130436017/f3014b1f409.pdf
    • http://www.liveyoursovereignlife.com/uploads/1/3/0/6/130605048/rirusogazozivun-rululesojododor-kexirifu-fuzos.pdf
    • http://kodzie.com/uploads/1/3/0/4/130488243/vasataromuwa.pdf
    • http://thealbatrosslounge.com/uploads/1/3/0/6/130604226/wujasilujezazijixik.pdf
    • http://cdizzlerocks.com/uploads/1/3/0/3/130323384/muwumebadexo-zetilazuv-duduxug-zijogumed.pdf
    • http://cams-collection.com/uploads/1/3/0/7/130738765/2d9f510c2e0985b.pdf
    • http://ugjw.brdge.org/uploads/1/3/0/5/130589252/130589252.html#ielts+for+academic+purposes+listening+test+5+answers
    • http://ericamcquiddypsyd.com/u

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000031ad.bin
23349687faa50d3920027c0ee91a8145f7da6a5ad1edaf2c030c1c5abebd5da0
pdf-font-stream PDF embedded font (sfnt) at offset 0x31AD 7664 bytes