Malicious PDF — malware analysis report

Static analysis result for SHA-256 973a43705969cdbe…

MALICIOUS

PDF

41.3 KB Authoring application: Poppler-utils
MD5: da91a62c43800037f237fcd83170c32f SHA-1: a6352a0816e1d8705b80536de005041d5ef3fae7 SHA-256: 973a43705969cdbe1c95f22306ff6e21c87fcb0bf0e53d103d0f596c3f2b8b3c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, a technique often used for SEO manipulation or to redirect users to malicious sites. ClamAV identified this as Pdf.Phishing.TtraffRobotInstall, and ML classifiers strongly agree with the malicious verdict. The embedded URLs are the primary IOCs, pointing to a link farm hosted on various domains.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://childrensliteratureassembly.com/uploads/1/3/0/5/130588605/pefitevem_najipiko.pdf
    • http://joy-by-design.org/uploads/1/3/0/5/130588861/c8eb34257a3.pdf
    • http://thisislark.com/uploads/1/3/0/6/130604804/7197624.pdf
    • http://www.nomadicwellness.com/uploads/1/3/0/4/130494059/8815032.pdf
    • http://mta-sts.mail.yourchoicepettransport.com/uploads/1/3/0/7/130739060/f79b5a.pdf
    • http://nelslehtinen.com/uploads/1/3/0/5/130588457/vozinewojigi-rixofusokete.pdf
    • http://austincustomshop.com/uploads/1/3/0/8/130873802/xokeverufog-bukosilul-geparav-pexifinenunir.pdf
    • http://mayaarchaeology.net/uploads/1/3/0/8/130814234/binun-jemup-falevis.pdf
    • http://saferescuefordogs.com/uploads/1/3/0/6/130604508/sotutilelove.pdf
    • http://www.noon649.org/uploads/1/3/0/6/130604737/fagomekotojiriguvile.pdf
    • http://kreativekidsworld.com/uploads/1/3/0/4/130436006/130436006.html#ncert+8th+class+english+grammar+book+pdf
    • http://mta-sts.mail.yourchoicepettransport.com/u

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000032db.bin
4ea368a6205a9a61516b214fad296f4c1a061e4d408352a5b1e3006b75395c5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x32DB 8444 bytes
font_01_sfnt_off00004b92.bin
54a67f18f7804fa767ee80a56b7ae82ff0ece89811b53a8b702333d36323999f
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B92 7756 bytes