Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b7e4c2e67fe96f8…

MALICIOUS

PDF

37.0 KB Authoring application: Nitro PDF
MD5: 2b291fd9473306a4cd0f4536760fc18e SHA-1: 2a907e5036631a26074eb052cdef7c288a60d26c SHA-256: 8b7e4c2e67fe96f8216c22bd4a2fd99565c9b71799077f769dee8a8e52760d4c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a mass external link farm, directing users to numerous other PDF files hosted on various domains. The document body, though heavily obfuscated, appears to be a cover letter for postdoc positions, suggesting a social engineering lure. The primary heuristic, PDF_SEO_LINK_FARM, indicates a high volume of outbound links designed to appear as legitimate content, likely to distribute further malicious payloads or engage in phishing. The ML classifier and ClamAV detection strongly support the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mail.xenastrategies.com/uploads/1/3/0/4/130476700/falazep.pdf
    • http://darwinlazatinphotography.com/uploads/1/3/0/8/130813855/gigiwisilamabud.pdf
    • http://amazethemepark.com/uploads/1/3/0/8/130814960/rilutoninukepi.pdf
    • http://clarazul.com/uploads/1/3/0/7/130775934/3239270.pdf
    • http://www.savemundypondpark.com/uploads/1/3/0/6/130621176/083ba50c5b8c0.pdf
    • http://virginiaveterinaryconsultants.net/uploads/1/3/0/6/130605312/6198781.pdf
    • http://korvinus-production.com/uploads/1/3/0/2/130288364/mazodekopudi-sisekav-diwowi.pdf
    • http://smartsell.work/uploads/1/3/0/2/130289304/ee5701cb95a.pdf
    • http://cpanel.elevatecbdcosmetics.com/uploads/1/3/0/6/130639765/sozezurezolerutig.pdf
    • http://hostmaster.theexoticanimalencounter.co.uk/uploads/1/3/0/6/130604202/xabaxugogavetu_gexerumuzo_kamezipules.pdf
    • http://duty.af/uploads/1/3/1/0/131070036/335d1fe313f.pdf
    • http://ccteenwriters.com/uploads/1/3/0/4/130476263/7988224.pdf
    • http://smc-realty.com/uploads/1/3/0/7/130776605/vutixamibujetan_setakebugavodiv_tedaxolefatibij_madenazarinikef.pdf
    • http://anthemtechsupport.com/uploads/1/3/0/7/130776529/8440955.pdf
    • http://commongroundsphilly.com/uploads/1/3/0/7/130775536/650c51a7fa9.pdf
    • http://claysmithwrites.com/uploads/1/3/0/7/130740207/kopufiwoweve-solovuzusowu-ronel-meritepuz.pdf
    • http://exclusivetrendsetters.com/uploads/1/3/0/5/130590325/miwaxarosoxiwazodana.pdf
    • http://grupomarin.net/uploads/1/3/0/5/130588222/jadobejupisogu.pdf
    • http://www.maconyoga.studio/uploads/1/3/0/4/130488365/a5de488f28cca.pdf
    • http://spectrum-globalmarketing.com/uploads/1/3/0/5/130539913/kadomavozarikunal.pdf
    • http://liesandnews.com/uploads/1/3/0/3/130312968/bigitosudabem_lotokiwi_tofixagurisa_tajerupibev.pdf
    • http://webmail.themodestshoptx.com/uploads/1/3/0/5/130550770/130550770.html#cover+letter+for+postdoc+positions
    • http://commongroundsphilly.com/uploads/1/3/0/7/130775536/650c51a

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030bd.bin
216a6540446fb9b780e5551fc51c984974a2662ca5d63d80c5f120be4763e938
pdf-font-stream PDF embedded font (sfnt) at offset 0x30BD 7416 bytes