Malicious PDF — malware analysis report

Static analysis result for SHA-256 884013a758b4d7d3…

MALICIOUS

PDF

51.6 KB Authoring application: Mobipocket Creator
MD5: 308aaa398b2fbc8e583e5eed6779fa34 SHA-1: 042123fc95e031147c4e0bc135ec4850df3b139f SHA-256: 884013a758b4d7d355e9726fc6e97beef97dbdc673c3d1c41119a0b88239db03
202 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a mass external link farm, with 20 links pointing to other PDFs, indicating a SEO-based distribution strategy. The document body, though heavily obfuscated, combined with the 'SE_ADVANCE_FEE_SCAM_LURE' and 'SE_MFA_LURE' heuristics, suggests the primary intent is to trick users into clicking malicious links under the guise of prize notifications or account verifications, likely for credential harvesting or further malware delivery. The ClamAV detection further confirms its malicious nature.

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://chitowngala.com/uploads/1/3/0/7/130776649/9589576.pdf
    • http://abogadospluralistas.org/uploads/1/3/0/7/130740573/1778803.pdf
    • http://brettcross.net/uploads/1/3/0/6/130639531/8143741.pdf
    • http://cupcakecomeback.com/uploads/1/3/0/5/130588780/7360085.pdf
    • http://www.jaymichaelgilman.com/uploads/1/3/0/7/130738892/pumosoxi_tosoneve.pdf
    • http://root.h-a-r-t.org/uploads/1/3/0/7/130776164/ridageba-kukoseb-dapopavelawubag.pdf
    • http://www.easeupyourlife.com/uploads/1/3/0/7/130775331/2b9dfa.pdf
    • http://minhavidaminhasescolhas.com/uploads/1/3/0/2/130272254/jomukawaz_xewimunom.pdf
    • http://dvvap.org/uploads/1/3/0/4/130489019/1856561.pdf
    • http://mx.kammcreekfarm.com/uploads/1/3/0/6/130639611/rorep_mufokabalaj.pdf
    • http://whymegandoonan.com/uploads/1/3/0/3/130379061/2178261.pdf
    • http://mail.stop-roken-coach.nl/uploads/1/3/0/5/130590763/newiluditixe.pdf
    • http://mta-sts.mail.ibew23.org/uploads/1/3/0/2/130288630/genafidilebipok.pdf
    • http://mail.jessicamiyuki.com/uploads/1/3/0/5/130544257/sazefewuso-folibatixovofon-nerenevipeje-zililejeju.pdf
    • http://bubblesoccergeelong.com.au/uploads/1/3/0/7/130738778/d33f2.pdf
    • http://christianefontaine.com/uploads/1/3/0/5/130539113/613735.pdf
    • http://sportskidsplay.com/uploads/1/3/0/5/130588787/wirememok.pdf
    • http://www.muhammadsrsabry.us/uploads/1/3/0/6/130604177/xumedojesagadax.pdf
    • http://mahgdalenrose.com/uploads/1/3/0/2/130271154/rufulefumasotudorapi.pdf
    • http://nelslehtinen.com/uploads/1/3/0/5/130550827/9211fc9b.pdf
    • http://pbjconstructionllc.com/uploads/1/3/0/3/130313836/130313836.html#airtel+dth+change+base+package

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005058.bin
32b54217619f9438721b423dc2f4f4da0f78781b0811ea49af2be6b0310ecf56
pdf-font-stream PDF embedded font (sfnt) at offset 0x5058 16164 bytes
font_01_sfnt_off0000686e.bin
dcc06d952967721f420b69aa0fd14c2c1aa73c1ca76b35515ae84b7d6713c2e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x686E 8760 bytes