Malicious PDF — malware analysis report

Static analysis result for SHA-256 84a4bcc1da5382ea…

MALICIOUS

PDF

35.8 KB Authoring application: Mobipocket Creator
MD5: efb91b0ca46db3b8d1feb0aad7bfbc83 SHA-1: 6b7c81d4c892dbe6dde085874dc20a1637c4d1b5 SHA-256: 84a4bcc1da5382ea73f3ff9799df09e62d200e1f96630a7bb82a4838e3ecc289
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to distribute further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware delivery. The primary attack pattern involves directing users to a network of suspicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://therutor.tech/uploads/2020/01/28/1910894.pdf
    • https://kefegujivetixo.weebly.com/uploads/1/3/0/4/130435639/muxuwepa.pdf
    • http://fema.trokot-shops.pro/uploads/2020/01/29/4755658.pdf
    • http://zokeru.friendlylazur.com/uploads/2020/01/27/kopek_fumitot_nuvode_sonos.pdf
    • https://tukumidapibax.weebly.com/uploads/1/3/0/5/130550915/ruxiwuneg.pdf
    • http://bot.sber-home.info/uploads/2020/01/29/beveturemapamam.pdf
    • https://muxuruwakik.weebly.com/uploads/1/3/0/5/130589220/zuzigejewogopa.pdf
    • https://vijebefamitim.weebly.com/uploads/1/3/0/4/130483928/1522756.pdf
    • https://zobawiloro.weebly.com/uploads/1/3/0/2/130289428/luparid_mewikilosamu.pdf
    • http://svh-expert.ru/uploads/2020/01/27/vedok_loxapuv_porewivo.pdf
    • https://morarafaf.weebly.com/uploads/1/3/0/5/130590224/130590224.html#stroke+anticoagulation+guidelines+2016

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001255.bin
695f35cd8a37c7d361df02df314624a70f262ca84ca217fc2f741f83ae4e64c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1255 7680 bytes