Malicious PDF — malware analysis report

Static analysis result for SHA-256 95dbee663482796a…

MALICIOUS

PDF

39.4 KB Authoring application: Smallpdf Desktop First seen: 2020-09-24
MD5: dc41a4af53cf0768cf53a5561d02810a SHA-1: a61e53ca34d63bb0bb4b9502f96af916974a333c SHA-256: 95dbee663482796ae508ee366e1360584916c26fdc75a6a910f9abec226acd37
212 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, many pointing to raw IP addresses and suspicious domains, designed to lure users into downloading further malicious content. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the critical heuristic 'PDF_SEO_LINK_FARM' strongly indicate a phishing or malware distribution campaign. The document body's text, while partially corrupted, includes phrases related to movie listings, suggesting a social engineering pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://95.217.124.64/uploads/2020/01/29/2465121.pdf PDF link annotation
    • http://pizixiz.droneportal.ru/uploads/2020/01/28/redise.pdfIn PDF document text
    • http://onlinesecurityservice.site/uploads/1/3/0/5/130588702/6029702.pdfIn PDF document text
    • http://zoberaja.magimafr.ovh/uploads/2020/01/28/6866558.pdfIn PDF document text
    • http://barringtonmiddleschoolpto.com/uploads/1/3/0/7/130775983/vonunidagex.pdfIn PDF document text
    • http://nicole-florio.com/uploads/1/3/0/2/130287211/130287211.html#website+untuk++film+bioskop+indonesiaIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001048.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1048 7680 bytes
SHA-256: 298ba38c2cf7cb3b218bc76351b1477fc2c721ada2a6b0a147a25c1c75a885b2
font_01_sfnt_off00005299.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5299 16268 bytes
SHA-256: 5d7ebd720715cd86529581f1d40cc643f68465477bd430d4be5ff736bc95f798