Malicious PDF — malware analysis report

Static analysis result for SHA-256 79fe7dbad3669693…

MALICIOUS

PDF

37.7 KB Authoring application: OpenOffice Draw First seen: 2020-09-24
MD5: 6590bedf7df07c3a2fa64768781f6945 SHA-1: b186f40f22693aeec8cb8d1e45acd099e3b943ef SHA-256: 79fe7dbad36696932c261927880e220b4dafd2dd251934e74bccdd01ac99f1e3
192 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links to external PDF files hosted on various domains, indicating a link farm or redirection strategy. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output strongly suggest malicious intent, likely phishing or malware distribution. The embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sapek.wiki-energie.com/uploads/2020/01/29/poxajonexadixu.pdf In PDF document text
    • http://negocioscontra.com/uploads/1/3/0/4/130483402/4313184.pdfIn PDF document text
    • http://nottinghamkickboxing.com/uploads/1/3/0/5/130544625/gopakagigemaz.pdfIn PDF document text
    • http://nirvanastorage.net/uploads/1/3/0/4/130436136/xukalujaj.pdfIn PDF document text
    • http://lets-split.com/uploads/1/3/0/6/130604612/zizoz.pdfIn PDF document text
    • http://northoakdesign.com/uploads/1/3/0/6/130639626/filisutibegasolara.pdfIn PDF document text
    • http://sax.moiklining.ru/uploads/2020/01/28/5194693.pdfIn PDF document text
    • http://resonancetapexperience.com/uploads/1/3/0/6/130621284/578790.pdfIn PDF document text
    • http://lorenamartinezhomes.com/uploads/1/3/0/6/130620573/692769.pdfIn PDF document text
    • http://naturalhand.net/uploads/1/3/0/4/130476135/pakaxi.pdfIn PDF document text
    • http://peake.design/uploads/1/3/0/4/130435821/75bcc640b3af.pdfIn PDF document text
    • http://smoothtransitionservices.com/uploads/1/3/0/5/130588403/varimesuvegelo.pdfIn PDF document text
    • http://antiviruseprotectserviceonline.site/uploads/1/3/0/7/130738890/130738890.html#cancer+awareness+clip+art+freeIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001296.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1296 7844 bytes
SHA-256: 4d7f9990c6eecbf7fbeaf09aec91400da486e4d0524db949cad8290586191ebf