Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b80ed5706944f9e…

MALICIOUS

PDF

66.1 KB Authoring application: PDF Studio
MD5: 379c722fa8dbf558303be34247831d40 SHA-1: 97a99dd96af434f6b21513a851ee97ba7b77b2b8 SHA-256: 8b80ed5706944f9e692281b82d3af0e51d188b109ea04e42819a06e5f149dda7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, for malicious content. The primary attack pattern identified is a link farm, with 31 external PDF links embedded within the document. These links likely serve to direct users to malicious content or phishing sites, as indicated by the ClamAV detection name 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bioenergetichealing888.com/uploads/1/3/0/7/130738966/6254489.pdf
    • http://selfmixinghennadye.com/uploads/1/3/0/5/130590336/dikov.pdf
    • http://ilovestan.info/uploads/1/3/0/4/130483447/mejamuxi.pdf
    • http://www.nodesiahernandez.com/uploads/1/3/0/4/130476586/taxiruluv.pdf
    • http://wegotyoufoundation.org/uploads/1/3/0/3/130323968/7932736.pdf
    • http://www.nelsonsoutdoors.com/uploads/1/3/0/2/130270996/2361386.pdf
    • http://rentalsandroommates.net/uploads/1/3/0/6/130621980/4786372.pdf
    • http://mountain-ammo.com/uploads/1/3/0/2/130288562/tejiko_xenurub.pdf
    • http://tapleydugas.com/uploads/1/3/0/6/130639565/7695987.pdf
    • http://lexigoldberg.com/uploads/1/3/0/3/130323157/7593041.pdf
    • http://annabelchiarelli.org/uploads/1/3/0/6/130639775/sesokekonabobixu.pdf
    • http://www.adentanewzealand.com/uploads/1/3/0/5/130539494/mexixagozoban_wemusevok_bugibawerojus.pdf
    • http://thehealthynibbler.com/uploads/1/3/0/6/130640200/menal.pdf
    • http://materialsmatter.net/uploads/1/3/0/4/130488308/8741143.pdf
    • http://dmicreativemanagement.com/uploads/1/3/0/8/130873946/4224953.pdf
    • http://santafedatahub.com/uploads/1/3/0/4/130435722/sojige_logesosutilolez_lunenasi_wopaxep.pdf
    • http://theathelitefactory.com/uploads/1/3/0/3/130323315/1701202.pdf
    • http://missloud.com/uploads/1/3/0/6/130639458/6980693.pdf
    • http://lovellabridal.net/uploads/1/3/0/3/130313049/276403.pdf
    • http://veganoptions.shop/uploads/1/3/0/5/130543210/temiguzoronige.pdf
    • http://rcaleel.com/uploads/1/3/0/5/130550812/degemovim_sazeleje.pdf
    • http://tdz539.bdgct.com/uploads/1/3/0/7/130740375/130740375.html#hernia+discal+cervical+c5+c6

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000018ac.bin
63ca00b7b92768820a9967c05aedb3a699d2879d7245d48bc0d27f6f01dc6cf6
pdf-font-stream PDF embedded font (sfnt) at offset 0x18AC 9204 bytes