Malicious PDF — malware analysis report

Static analysis result for SHA-256 879e60a25a72b6c0…

MALICIOUS

PDF

35.4 KB Authoring application: pdf-parser
MD5: d92fee9a7a08dd6b6067204cc0827b7a SHA-1: 768b969f21d0f6b49a648acdc6395cb188d2147f SHA-256: 879e60a25a72b6c0389dc70be55e8e727e3312b9726c951c92d42ba3cc5da937
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file exhibits characteristics of a link farm, embedding a large number of external URLs that point to other PDF documents. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for SEO manipulation or to distribute further malware. The embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rudewozuro.220602shopsss08.fun/uploads/2020/01/28/rijinobovajowi.pdf
    • http://pulezu.avtosvet24.ru/uploads/2020/01/29/kezevapafajipevolo.pdf
    • https://tuwakazununizof.weebly.com/uploads/1/3/0/3/130323341/eb08664c98851.pdf
    • https://faxurepowiz.weebly.com/uploads/1/3/0/5/130546543/zagatokojov.pdf
    • http://wifasid.tricolor-volokamske.ru/uploads/2020/01/28/9838691.pdf
    • http://rera.remontkamazov.ru/uploads/2020/01/28/jexolapul-simax.pdf
    • http://lookerinsider.com/uploads/1/3/0/5/130589208/5445644.pdf
    • http://thesuspiciouscarrot.com/uploads/1/3/0/6/130620390/pufiwebojamugoxe.pdf
    • https://peluburezawin.weebly.com/uploads/1/3/0/3/130323409/paxakinat-wudepumutekim-buzuralebob-pevavokoj.pdf
    • https://maxelokitemaf.weebly.com/uploads/1/3/0/3/130323384/vugik-patozizesujok.pdf
    • http://fiz.speacetech.us/uploads/2020/01/28/dawimuxanotu_lowumifobigo_wamaxufan_vimarowufuzelap.pdf
    • http://missgojo.com/uploads/1/3/0/2/130287894/130287894.html#sublet+room+agreement+uk+template

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001343.bin
10a3caa8f8c62ab7807ea3f2c216c8398ac514a4435848ed39662ac61608f268
pdf-font-stream PDF embedded font (sfnt) at offset 0x1343 7964 bytes