Malicious PDF — malware analysis report

Static analysis result for SHA-256 7cf81bb2a84cc645…

MALICIOUS

PDF

36.9 KB Authoring application: Nitro PDF First seen: 2020-09-24
MD5: 2ab6ccd0b2e7f8534061a66e0ee45d44 SHA-1: 29dd0754169869f161765cc656a3360a9106f259 SHA-256: 7cf81bb2a84cc64579e7ba97d226ce87e4b57710d7826fa028a5dc0f6e73a880
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files on different domains. This suggests a campaign to manipulate search engine results or distribute additional malicious content. The ClamAV detection and ML classifier further support its malicious nature, classifying it as Pdf.Phishing.TtraffRobotInstall.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sugartreesoda.com/uploads/1/3/0/4/130483980/xikidaju-nudevita.pdf In PDF document text
    • http://thehalos.com/uploads/1/3/0/7/130739076/fobokubilox_pojuvisozolos_xuxidojiw.pdfIn PDF document text
    • http://www.dj4rain.com/uploads/1/3/0/2/130272232/8480272.pdfIn PDF document text
    • http://wireless-stop.com/uploads/1/3/0/5/130538842/e350bf9f2b518.pdfIn PDF document text
    • http://bluesheeppainting.com/uploads/1/3/0/5/130546118/4518540.pdfIn PDF document text
    • http://shanghaigourmet.us/uploads/1/3/0/5/130541443/sipemukojow.pdfIn PDF document text
    • http://shrutiformoco.com/uploads/1/3/0/8/130873863/09d4e98923ae.pdfIn PDF document text
    • http://www.eserveway.com/uploads/1/3/0/7/130740617/9228204.pdfIn PDF document text
    • http://floydfx.com/uploads/1/3/0/5/130588443/bupebuda-tafel-xilawoz-varav.pdfIn PDF document text
    • http://trainingcenterchurches.com/uploads/1/3/0/6/130621666/c540ecb.pdfIn PDF document text
    • http://www.collectivechicago.com/uploads/1/3/0/6/130640090/vakevu-vebapukulunimo-mekewa.pdfIn PDF document text
    • http://www.ezbcbd.com/uploads/1/3/0/6/130603690/vetotojisozixupetif.pdfIn PDF document text
    • http://marchettispaghetti.com/uploads/1/3/0/5/130538945/4933344.pdfIn PDF document text
    • http://cumbriachoralinitiative.org/uploads/1/3/0/4/130488328/3194591.pdfIn PDF document text
    • http://californiaspac.com/uploads/1/3/0/5/130539113/1137098.pdfIn PDF document text
    • http://roosterpr.agency/uploads/1/3/0/3/130379921/sajunax.pdfIn PDF document text
    • http://beatzbylex.com/uploads/1/3/0/4/130488417/2c72ed9633.pdfIn PDF document text
    • http://rqgenesis.co/uploads/1/3/0/4/130489914/makunudemosolosek.pdfIn PDF document text
    • http://wcd-7904t1u.mgh-r.ch/uploads/1/3/0/6/130605012/130605012.html#rumen+physiology+pdfIn PDF document text
🗂 Part of campaign: bluesheeppainting.com 6 samples

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000343b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x343B 7352 bytes
SHA-256: 35ff8be33d0747de67e1ac7406280daae9cad8f2ccad5977bddb04be22ad2d24