Malicious PDF — malware analysis report

Static analysis result for SHA-256 96e6a74e3d91163d…

MALICIOUS

PDF

30.8 KB Authoring application: OpenOffice Draw
MD5: aa10d031d2dbdfe4ed0e4e9e6dddcf9a SHA-1: f05a4917c5a9409719bd619433b7049f67a5d894 SHA-256: 96e6a74e3d91163d971c360875c1ca13ee0f71d4cca3d0cf2a43cfab07867869
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files hosted on various domains, as indicated by the PDF_SEO_LINK_FARM heuristic. This suggests a coordinated effort to direct users to potentially malicious content. The ML classifier and ClamAV detection further support the malicious nature of the file. The document body itself is largely garbled but contains references to 'Circulatory system worksheets doc', which appears to be a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://teplinfinancial.com/uploads/1/3/0/4/130436362/8818023.pdf
    • http://iqseries.de/uploads/1/3/0/5/130539260/03bf42fd4.pdf
    • https://kivorogenakevov.weebly.com/uploads/1/3/0/5/130590700/morexod.pdf
    • http://milanchurch.com/uploads/1/3/0/6/130604180/2264292.pdf
    • http://myflexbrace.com/uploads/1/3/0/2/130288364/801124.pdf
    • http://daveict.com/uploads/1/3/0/3/130379676/toxutulikivad.pdf
    • http://gwenjacksonstories.net/uploads/1/3/0/8/130814992/130814992.html#circulatory+system+worksheets+doc

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001019.bin
383a0461c5e72a326860d895954c33a58b43934250e9f12770082806d6e5e601
pdf-font-stream PDF embedded font (sfnt) at offset 0x1019 7288 bytes