Malicious PDF — malware analysis report

Static analysis result for SHA-256 82d32aa3952ee7d7…

MALICIOUS

PDF

39.3 KB Authoring application: Serif PagePlus
MD5: 87ada9fa0db1fb974841fb897ea401d7 SHA-1: 1d975457d9eebf26b8a4736a05b6afbed1cefb43 SHA-256: 82d32aa3952ee7d7f88597efb2443c7a0cd1428933cafb65c41ae15f90bb79bf
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file was identified as malicious by ClamAV, specifically as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. Static analysis revealed a significant number of embedded URLs pointing to PDF files on various domains, indicating a link farm strategy. The document body text is heavily corrupted and unreadable, providing no direct clues to its intent. The primary attack pattern observed is the distribution of numerous external PDF links, likely to manipulate search engine results or to serve as a distribution point for further malicious payloads.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.dampdogbooks.co.uk/uploads/1/3/0/4/130488399/luwuropa.pdf
    • http://rvsolarpanelpros.com/uploads/1/3/0/5/130551684/fizidurunigunot-vuvuvutirirapi-naxesurikuxesun.pdf
    • http://babymyo.com/uploads/1/3/0/5/130589374/6671836.pdf
    • http://powerstrokeconcepts.com/uploads/1/3/0/4/130490301/3700987.pdf
    • http://www.purejoyce.com/uploads/1/3/0/7/130775050/1170608.pdf
    • http://krgabogados.com/uploads/1/3/0/6/130620847/0f27e7bec1.pdf
    • http://casarefugiopa.org/uploads/1/3/0/3/130379423/f5662e25409f.pdf
    • http://leadingchristianity.com/uploads/1/3/0/2/130287221/1004797.pdf
    • http://detroitfitclub.com/uploads/1/3/0/4/130476074/wowoxazekikilut_jevefefafobodiz_xovagis.pdf
    • http://typeemup.com/uploads/1/3/0/5/130544257/1168512.pdf
    • http://www.thecandistore.com/uploads/1/3/0/9/130969758/wavukumibuvozajige.pdf
    • http://medikamentekaufen.com/uploads/1/3/0/6/130620395/6708be8f624c9.pdf
    • http://mylifewater.nl/uploads/1/3/0/4/130436166/6473741.pdf
    • http://primeclassutah.com/uploads/1/3/0/5/130550774/jujepegasowiza.pdf
    • http://tulsawindowtinter.com/uploads/1/3/0/2/130289333/kapatazomupuka_mopelitenora_vasedi.pdf
    • http://norvelfinancialsolutions.com/uploads/1/3/0/6/130604640/7f2c0a7e653.pdf
    • http://chuyitos.com/uploads/1/3/0/6/130604805/firudo-gonipatamokukob-rilaron.pdf
    • http://vinculumartfinance.com/uploads/1/3/0/5/130588394/lexepubas.pdf
    • http://www.vivianoberfeldmft.com/uploads/1/3/0/6/130621228/14e462f04f0.pdf
    • http://www.seftonroofing.co.uk/uploads/1/3/0/4/130476013/xazevozevixojikeda.pdf
    • http://drive2retire.com/uploads/1/3/0/4/130489230/lirinamipobime-rojidefepatil-dekel.pdf
    • http://messiniako-catering.com/uploads/1/3/0/7/130775640/1790312.pdf
    • http://demotivational-posters.com/uploads/1/3/0/7/130776031/5a5a4.pdf
    • http://noraflum.org/uploads/1/3/0/7/130739328/wumebagiwufa_lifikelu.pdf
    • http://marilusdesigns.com/uploads/1/3/0/6/130639226/130639226.html#scaled+agile+framework+pre-pi+planning
    • http://www.pure

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000036b8.bin
85ac45dc909cf675a9ab23658868eb519609f4ec14b9de51a4227b70d6d7abe5
pdf-font-stream PDF embedded font (sfnt) at offset 0x36B8 7744 bytes