Malicious PDF — malware analysis report

Static analysis result for SHA-256 85fb6c50fa4e39ef…

MALICIOUS

PDF

37.4 KB Authoring application: LibreOffice Draw First seen: 2020-09-15
MD5: 85c335109c23d9c8cfadfffd1a8d0767 SHA-1: 5dbdf2598e03938b9d6be716fa581b6c4a620316 SHA-256: 85fb6c50fa4e39ef53e19b1b94633c916ee15810e684d2fd75ae10551fa3429d
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious intent. The document body contains a large number of embedded URLs, suggesting a link farm designed to redirect users to potentially malicious content. The presence of these links and the overall detection strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://teamseoblasteo.weebly.com/uploads/1/3/0/5/130551000/58569.pdf In PDF document text
    • http://mercermovercompany.com/uploads/1/3/0/2/130272638/zalosujawaja_jeguvokuvesoxo_devamar_memepunedaxesug.pdfIn PDF document text
    • https://nosamazujire.weebly.com/uploads/1/3/0/5/130550867/c277a8df7f2e1c.pdfIn PDF document text
    • http://fibromyalgiamadesimple.com/uploads/1/3/0/4/130435988/5f03bc9.pdfIn PDF document text
    • http://missturquoisecircuit.com/uploads/1/3/0/2/130271224/dajinegasuvopa.pdfIn PDF document text
    • http://xubozonaw.1xbonus.info/uploads/2020/01/28/toradubuxi.pdfIn PDF document text
    • http://abramsflooring.com/uploads/1/3/0/2/130287883/dexutivakosu.pdfIn PDF document text
    • http://jukidisamu.sultantec.com/uploads/2020/01/28/fuvoboju.pdfIn PDF document text
    • http://momentcapture.net/uploads/1/3/0/6/130620955/b6e3e9.pdfIn PDF document text
    • http://thecraft2draft.com/uploads/1/3/0/4/130435694/8674f786aab318.pdfIn PDF document text
    • http://starfishcenter.org/uploads/1/3/0/5/130551053/a20f4806391.pdfIn PDF document text
    • http://kncompletehomeservices.com/uploads/1/3/0/5/130540937/nesojutabini.pdfIn PDF document text
    • http://keppingerlaw.com/uploads/1/3/0/6/130621597/421706.pdfIn PDF document text
    • http://citisecurities.in/uploads/1/3/0/5/130551586/89c79fd0a8371d.pdfIn PDF document text
    • http://create218.org/uploads/1/3/0/5/130550898/692f1c478e8.pdfIn PDF document text
    • http://rckrepost.online/uploads/2020/01/28/gutepomorama_rezovepukofipu_nutebubomeve_sewasijenu.pdfIn PDF document text
    • http://ankezimmermann.ca/uploads/1/3/0/6/130621915/130621915.html#css+grid+template+freeIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001673.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1673 8352 bytes
SHA-256: 61415ead3ba348a430f6d34c9ae16e6d32445943c794ce5f9c40e1157c68a91b