Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e3450c135d76a49…

MALICIOUS

PDF

40.9 KB Authoring application: Mobipocket Creator First seen: 2020-09-24
MD5: fed532dafc4d2e3957f234ccbdb336ca SHA-1: d298832f9b6a029b6abf925859c26c9fb3dcac1a SHA-256: 7e3450c135d76a4909fb1ed27f44aedcb45af88e37f0956f81f522fb16b8a0bd
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document was flagged by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0 and an ML classifier indicated a high probability of maliciousness. The heuristic PDF_SEO_LINK_FARM indicates the presence of a large number of external PDF links, suggesting a link farm or redirection mechanism. The embedded URLs likely serve to distribute further malicious content or lead users to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wolvescampradio.com/uploads/1/3/0/4/130479435/3ca0c157f7010.pdf In PDF document text
    • http://webdisk.byhp.org.uk/uploads/1/3/0/6/130605153/1532059.pdfIn PDF document text
    • http://3pfd.com/uploads/1/3/0/6/130604101/68809916379f0.pdfIn PDF document text
    • http://montbrae.com/uploads/1/3/0/5/130540359/b07310b.pdfIn PDF document text
    • http://relaysocial.net/uploads/1/3/0/5/130550857/tujoravosati.pdfIn PDF document text
    • http://motusbehaviors.com/uploads/1/3/0/3/130379206/juguso.pdfIn PDF document text
    • http://lsrealty.co/uploads/1/3/0/4/130476244/bufudebib.pdfIn PDF document text
    • http://jamistichter.com/uploads/1/3/0/7/130775029/3100810.pdfIn PDF document text
    • http://marriagemotherhoodmenopause.com/uploads/1/3/0/6/130639221/8128418.pdfIn PDF document text
    • http://nutritioncapecod.com/uploads/1/3/0/6/130639701/polekevafede-matimoxebubapo-pedilijali-doxevumam.pdfIn PDF document text
    • http://plancul-reims.net/uploads/1/3/0/6/130604332/4ff9d85a437f1.pdfIn PDF document text
    • http://midwestlightingllc.com/uploads/1/3/0/6/130639110/fesel.pdfIn PDF document text
    • http://thetapbox.com/uploads/1/3/0/6/130620474/4485583.pdfIn PDF document text
    • http://izletiposrbiji.net/uploads/1/3/0/6/130620538/8538890.pdfIn PDF document text
    • http://6foot7dave.com/uploads/1/3/0/2/130289433/jifobesu.pdfIn PDF document text
    • http://prideofliars.net/uploads/1/3/0/4/130435943/nubefaloguzojosagam.pdfIn PDF document text
    • http://holagatito.com/uploads/1/3/0/2/130273623/8083838.pdfIn PDF document text
    • http://zevsmith.com/uploads/1/3/0/6/130621706/lesuxiwon.pdfIn PDF document text
    • http://vps9-internal.pleasingfood.com/uploads/1/3/0/5/130551684/130551684.html#cylindrical+roller+bearing+size+chart+skfIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000043a0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43A0 7652 bytes
SHA-256: 5be33a94df93df83ef3a3c24b68e00aa6ca5520d8c5b094cd43dec4b90e681cd