Malicious PDF — malware analysis report

Static analysis result for SHA-256 85feb93353c37117…

MALICIOUS

PDF

37.5 KB Authoring application: PDF Studio
MD5: 336005ae432ce4bdf2f321304f4cbe1e SHA-1: c81461dc391ca28960ae6ef25f8941e508d2feaf SHA-256: 85feb93353c37117db707a9acc0b5d2a28f4f23ce3f9c4c38077452a7069071c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded URLs pointing to other PDF files hosted on various domains. This behavior is indicative of a link farm or a distribution mechanism for further malicious content, as suggested by the ClamAV detection and ML classifier. The embedded URLs are likely intended to direct users to potentially malicious or unwanted content, or to manipulate search engine rankings.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lholmesnycschools.com/uploads/1/3/0/6/130620209/nozixom_tuxajewakukoka.pdf
    • http://mail.allsaintsmemorial.org/uploads/1/3/0/7/130776657/67fd011.pdf
    • http://vintagehomecharleston.com/uploads/1/3/0/6/130639903/5222003.pdf
    • http://approachquote.com/uploads/1/3/0/3/130313252/ninidasak.pdf
    • http://taterbucks.com/uploads/1/3/0/7/130739601/c90eab4daf0d16.pdf
    • http://automatedsalesrocket.com/uploads/1/3/0/3/130313755/lozizenu.pdf
    • http://caralarmnetwork.com/uploads/1/3/0/4/130476491/giwazida.pdf
    • http://twentiesandconfused.com/uploads/1/3/0/7/130776168/muxorubiravix_wovuneburekisu.pdf
    • http://royalboats.us/uploads/1/3/0/4/130483928/nurewipasafo-kudasivodiluwu-xemukudenid.pdf
    • http://www.amicusacorn.com/uploads/1/3/0/7/130776366/vopinemifufeja.pdf
    • http://lmathletics.org/uploads/1/3/0/7/130739533/vitaruvijotunix.pdf
    • http://mahatmadasitalia.com/uploads/1/3/0/6/130603841/datidale-napetux-wajogitajovuxi.pdf
    • http://newburyparkacupuncture.com/uploads/1/3/0/6/130604311/risagifoju_dasitezelika_gutijuxa.pdf
    • http://nancytangles.com/uploads/1/3/0/6/130604270/2551769.pdf
    • http://sacredgeometryibiza.com/uploads/1/3/0/7/130776356/6166155.pdf
    • http://whitneyswings.com/uploads/1/3/0/2/130288939/tinun.pdf
    • http://oakridgestables.co.uk/uploads/1/3/0/5/130538817/3141928.pdf
    • http://cpanel.helensdaughters.com/uploads/1/3/0/2/130289583/9cfd7.pdf
    • http://mosaiclearning.org/uploads/1/3/0/6/130620232/zezimomabox-xipenibavifi-ganidadatesuw-jolejalivedat.pdf
    • http://zs-development.com/uploads/1/3/0/2/130287462/d368dc556318e28.pdf
    • http://theblockhousecafe.com/uploads/1/3/0/7/130740200/saxufimugovanisa.pdf
    • http://mycbmc.com/uploads/1/3/0/3/130379635/vupusaw.pdf
    • http://citronaut.com/uploads/1/3/0/7/130775997/6730524.pdf
    • http://purchase-good.com/uploads/1/3/0/5/130551294/e83a2623b44.pdf
    • http://kingshotelsmunichfirstclass2.devsite-1.com/uploads/1/3/0/4/130488832/130488832.html#motivation+letter+sample+master+application

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030c1.bin
7a2ec1142c5d9fa6f521f6c3b5f726246fe7d2c4fe1d5dbb922144ef873d04bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x30C1 7148 bytes