Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d67b95b11c4decb…

MALICIOUS

PDF

42.8 KB Authoring application: GIMP First seen: 2020-09-24
MD5: b592e10f785c538e6aecd5749c633b75 SHA-1: d624efdf91bcee7e11e5d9b1e2111d50f4c902af SHA-256: 7d67b95b11c4decbb3f08083a19db391ab94d0d7ca7ea3bbd88a9a4f39344963
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a tactic to manipulate search engine results or distribute malicious content. The ClamAV detection and ML classifier further confirm its malicious nature, classifying it as Pdf.Phishing.TtraffRobotInstall. No scripts were extracted, but the presence of numerous external links indicates a likely phishing or content distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://libertybelleconcierge.com/uploads/1/3/0/3/130324004/wagoxoboxalik-xafusofosaj-simeduwetuz.pdf In PDF document text
    • http://100blackmen-stl.com/uploads/1/3/0/6/130605173/fifesufirejapix_duxonetenes_nadejiv_litekojakuxu.pdfIn PDF document text
    • http://gavakix.difmed.com/uploads/2020/01/28/8796761.pdfIn PDF document text
    • http://nogo.igorlucshii.online/uploads/2020/01/28/lolesozofevi-jelemep-bufanof-zinif.pdfIn PDF document text
    • http://zepefix.myopros.tech/uploads/2020/01/28/e95c3c146a.pdfIn PDF document text
    • http://officermnop.com/uploads/1/3/0/5/130543010/zopawiresepilatud.pdfIn PDF document text
    • http://dishingitupgame.net/uploads/1/3/0/6/130604288/jijijaguwulo.pdfIn PDF document text
    • http://thomasvasasphotography.shop/uploads/1/3/0/5/130588575/527244.pdfIn PDF document text
    • http://kathleenmaree.com/uploads/1/3/0/2/130288391/2235390.pdfIn PDF document text
    • http://tutorvirginia.com/uploads/1/3/0/4/130477533/dutomizopa-vazekotiwupud.pdfIn PDF document text
    • http://benkregel.com/uploads/1/3/0/5/130540725/130540725.html#oecd+education+2030+reportIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text
🗂 Part of campaign: jobs-kuechenhandel.org 3 samples

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001470.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1470 8220 bytes
SHA-256: d76dc870ce0db1e6d109d87ed2394b37ef4228c317a20db1f684c2ee60200904
font_01_sfnt_off00006c4b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6C4B 2628 bytes
SHA-256: ff90f76a01ccf9878a1088387a2b8e448e7dda08b241d7f0eb31b769938d48cf