Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a639e57716324f6…

MALICIOUS

PDF

84.0 KB Authoring application: Mobipocket Creator
MD5: 54ac8350dab77cb3c2a38389290941bf SHA-1: 531d47142e7e55417e74c3e768d031a743f0b4ec SHA-256: 7a639e57716324f67d02aeb84f99d91a028c8009a40d126021bcee311d1305f4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including a critical alert for a link farm containing 31 external PDF URLs. The ML classifier also assigned a high probability of maliciousness. The embedded URLs suggest a phishing or malware distribution attempt, likely using the PDF as a lure to direct users to malicious content hosted on external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thesongwritercircle.com/uploads/1/3/0/2/130289259/0f003242e49.pdf
    • http://konit.frirus.ru/uploads/2020/01/29/ea6c9a3cf8b011.pdf
    • http://sijujeli.site-elit.ru/uploads/2020/01/27/nenagexavo_fogara.pdf
    • http://robbietatebrickle.com/uploads/1/3/0/2/130287289/rimoj.pdf
    • http://wingluenwholesale.com/uploads/1/3/0/5/130540176/risixes-bitini.pdf
    • http://secondlives.biz/uploads/2020/01/28/6854070.pdf
    • http://gonaturaltips.com/uploads/1/3/0/6/130620530/junemerazok_fepugofokagulu.pdf
    • http://dudojid.my-sklad.ru/uploads/2020/01/28/lofomowajapomom-xozedozabinenog.pdf
    • http://bosigaba.credit-services.ru/uploads/2020/01/29/88ab447339dd4.pdf
    • http://bib.handorinservice.ru/uploads/2020/01/28/dinujubusid.pdf
    • http://pegipava.iamhasan.com/uploads/2020/01/27/gabozeda.pdf
    • http://bimplicity.net/uploads/1/3/0/5/130588729/780221.pdf
    • http://fieldhockeygoalkeeping101.com/uploads/1/3/0/4/130436139/8390912.pdf
    • http://saintjosephsquamish.com/uploads/1/3/0/5/130539940/tariravemovotudakaz.pdf
    • http://aikomatsuoka.com/uploads/1/3/0/4/130476519/f7de74c22b53.pdf
    • https://munajitab.weebly.com/uploads/1/3/0/5/130590521/nexuduguf-bolapolo-lesimafokalom.pdf
    • http://kiruk.novostroyki-barnaul.ru/uploads/2020/01/27/zijikonapexa_doniwepazesavak_romaminijimugo.pdf
    • http://bestrobloxhack.fun/uploads/2020/01/28/memobol.pdf
    • http://360kirk.com/uploads/1/3/0/4/130476221/fuvunipefalakat-xosuguligaru.pdf
    • http://cityglush12.icu/uploads/2020/01/28/wekalogivopazeweki.pdf
    • http://kimbaneconsulting.com/uploads/1/3/0/5/130538866/1529810.pdf
    • http://xebufivo.comparatuapuesta.com/uploads/2020/01/28/warekixavemo.pdf
    • http://segim.alianzaamericanadecolombia.com/uploads/2020/01/27/pojozixazelux.pdf
    • http://shopbelfast.info/uploads/1/3/0/6/130621383/130621383.html#video+editor+app++for+jio+mobile

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001370.bin
30a9cbe1f10d6fabd0ea811783aa5eb9ee73ed22b91e55bd0fe86aa131f5debb
pdf-font-stream PDF embedded font (sfnt) at offset 0x1370 8736 bytes