Malicious PDF — malware analysis report

Static analysis result for SHA-256 95dbee663482796a…

MALICIOUS

PDF

39.4 KB Authoring application: Smallpdf Desktop
MD5: dc41a4af53cf0768cf53a5561d02810a SHA-1: a61e53ca34d63bb0bb4b9502f96af916974a333c SHA-256: 95dbee663482796ae508ee366e1360584916c26fdc75a6a910f9abec226acd37
210 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, many pointing to raw IP addresses and suspicious domains, designed to lure users into downloading further malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the critical heuristic 'PDF_SEO_LINK_FARM' strongly indicate a phishing or malware distribution campaign. The document body's text, while partially corrupted, includes phrases related to movie listings, suggesting a social engineering pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://95.217.124.64/uploads/2020/01/29/2465121.pdf
    • http://pizixiz.droneportal.ru/uploads/2020/01/28/redise.pdf
    • http://onlinesecurityservice.site/uploads/1/3/0/5/130588702/6029702.pdf
    • http://zoberaja.magimafr.ovh/uploads/2020/01/28/6866558.pdf
    • http://barringtonmiddleschoolpto.com/uploads/1/3/0/7/130775983/vonunidagex.pdf
    • http://nicole-florio.com/uploads/1/3/0/2/130287211/130287211.html#website+untuk++film+bioskop+indonesia

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001048.bin
298ba38c2cf7cb3b218bc76351b1477fc2c721ada2a6b0a147a25c1c75a885b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1048 7680 bytes
font_01_sfnt_off00005299.bin
5d7ebd720715cd86529581f1d40cc643f68465477bd430d4be5ff736bc95f798
pdf-font-stream PDF embedded font (sfnt) at offset 0x5299 16268 bytes