Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d0b190e79fd766f…

MALICIOUS

PDF

54.2 KB Authoring application: Smallpdf Desktop
MD5: 4f3f90417acf16728645bb6b6b51c111 SHA-1: b811a896c962987ae433e9c974f5410ded1aa966 SHA-256: 7d0b190e79fd766f808f086212b8fc3da92e4cc5c96473ab4720eb38bae81c55
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO manipulation or to distribute further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as phishing. No scripts were extracted, and the document body content is heavily corrupted, preventing a more detailed analysis of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://municipalbondfraud.info/uploads/1/3/0/3/130379237/guzumuvapozog.pdf
    • http://metropolismexican-grill.com/uploads/1/3/0/5/130543588/fopemubi.pdf
    • http://xrdsfaith.com/uploads/1/3/0/6/130603838/gofajanunozelokiwovo.pdf
    • http://alexcapitalgroup.com/uploads/1/3/0/6/130620659/kufirusinurexef_wurizasuninakov_peruxugodufezap_nawoxireweb.pdf
    • http://ferrona.com/uploads/1/3/0/2/130292110/da15855bc3c.pdf
    • http://www.johnmasello.com/uploads/1/3/0/6/130620159/pizavonunu.pdf
    • http://myartscout.com/uploads/1/3/0/6/130605291/jezabofawowetowibeja.pdf
    • http://pureclassgeelong.com.au/uploads/1/3/0/4/130489377/topasaposaj_votogasidar.pdf
    • http://qor.kz/uploads/1/3/0/4/130435654/vusefidelusedul.pdf
    • http://davidchia.com/uploads/1/3/0/3/130323407/2284462.pdf
    • http://msjacksonsclass.com/uploads/1/3/0/4/130491075/duxib.pdf
    • http://360pro.be/uploads/1/3/0/7/130740141/wudonozaf.pdf
    • http://theposthospitalistcompany.org/uploads/1/3/0/6/130620679/xuvabemaf.pdf
    • http://almanaquecircular.com/uploads/1/3/0/7/130739007/8971212.pdf
    • http://www.goodtalkcounseling.com/uploads/1/3/0/4/130489800/135a86a44a8579.pdf
    • http://miavitta.com/uploads/1/3/0/6/130621997/3045907.pdf
    • http://barricas.nl/uploads/1/3/0/6/130620431/rikuwasunaril.pdf
    • http://ms-gillespie.com/uploads/1/3/0/8/130813557/4932175.pdf
    • http://mingateachers.com/uploads/1/3/0/8/130813784/mevamijiwuroja_zenefuze.pdf
    • http://hostmaster.musicalseedlings.co.uk/uploads/1/3/0/7/130739598/kedavadunizirujedase.pdf
    • http://linknoise.com/uploads/1/3/0/6/130621938/mabemin_gudofiseside_lofil_sizatuwisotizel.pdf
    • http://nabyou.com/uploads/1/3/0/5/130539866/kaguse.pdf
    • http://ewaveinc.com/uploads/1/3/0/5/130545249/130545249.html#life+processes+class+10+notes+byju%27s
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000509c.bin
e095e91abaa6d1533f8a6ffc429973194a90ddb23f1ee62b5c0aecaa106ec724
pdf-font-stream PDF embedded font (sfnt) at offset 0x509C 2824 bytes
font_01_sfnt_off000059fa.bin
1ecf4184025095b9dd82a94d09b3d5222d6507c48361a498b56883e28bdde309
pdf-font-stream PDF embedded font (sfnt) at offset 0x59FA 16084 bytes
font_02_sfnt_off00007173.bin
5869e39ec7fd0cbdd87f8a8bfaf03c8de98e175a0e013760ed70d2ebb41df7ae
pdf-font-stream PDF embedded font (sfnt) at offset 0x7173 8396 bytes