Malicious PDF — malware analysis report

Static analysis result for SHA-256 97620ce25f2592db…

MALICIOUS

PDF

57.1 KB Authoring application: ImageMagick
MD5: 73d28c463c1ad4fdea5ab365d96e2e70 SHA-1: a8e9d08b2075a5c53dd89c4edf759acc7d7722ff SHA-256: 97620ce25f2592db830cae08e6bc762c2d960ef6ab96d3b907236d08a81b1605
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links likely serve as a link farm to redirect users to malicious sites. The ClamAV detection further supports its malicious nature, classifying it as Pdf.Phishing.TtraffRobotInstall. No scripts were extracted from this sample, and the document body contained only chemical information unrelated to the malicious activity.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ivyandfluff.com/uploads/1/3/0/6/130639891/3462377.pdf
    • http://greysay.tech/uploads/1/3/0/8/130873863/ad41e.pdf
    • http://seaplanediving.com/uploads/1/3/0/7/130739221/toxipubi.pdf
    • http://lovelifeagain-lifecoachingmore.com/uploads/1/3/0/4/130483862/6a1686a4.pdf
    • http://rwbickfordconstruction.com/uploads/1/3/0/6/130640015/supizitipiwu.pdf
    • http://monikakrimendahl.com/uploads/1/3/0/7/130739221/bufagipimokan_tomosexadido_junevigatisef_xogasinefuva.pdf
    • http://earthstarweb.com/uploads/1/3/0/6/130604250/tibewelesizebefinix.pdf
    • http://morph-bcs.com/uploads/1/3/0/7/130739719/zigiwazosadapip.pdf
    • http://michaelsheacounselling.com/uploads/1/3/0/3/130313400/3685ba14d1.pdf
    • http://overcomeporn.org/uploads/1/3/0/4/130490036/nokafa_pomilol.pdf
    • http://rudgeramos.com/uploads/1/3/0/6/130603721/5495619.pdf
    • http://www.mtsuaxo.org/uploads/1/3/0/7/130775979/nopopepinokotu.pdf
    • http://cleansweepmusic.com/uploads/1/3/0/5/130589186/013d61ba351663e.pdf
    • http://abreanutrition.com/uploads/1/3/0/2/130270761/3017043.pdf
    • http://buckssmokingbbq.com/uploads/1/3/0/7/130775527/vivolesidavujit-vovarota.pdf
    • http://timeroll.com/uploads/1/3/0/3/130313075/3844674.pdf
    • http://terapiaregresiva.org/uploads/1/3/0/3/130313120/3484806.pdf
    • http://chattovoice.com/uploads/1/3/0/6/130639317/4114010.pdf
    • http://mangumcourtyards.com/uploads/1/3/0/5/130590257/1ba1bd2f7083.pdf
    • http://nesretreat.com/uploads/1/3/0/7/130738739/bozokev.pdf
    • http://novaimmobilien.eu/uploads/1/3/0/2/130271004/tomipowotipa_jijisegen.pdf
    • http://strobelightsforcars.net/uploads/1/3/0/6/130639161/878a8e30d81bb5.pdf
    • http://mysummerwithjack.net/uploads/1/3/0/3/130379315/f244a2.pdf
    • http://monetki.website/uploads/1/3/0/5/130550956/6414342.pdf
    • http://monetdiamondscollection.com/uploads/1/3/0/2/130271243/pezenowudibava-bapam-gawopologelemor-gurep.pdf
    • http://adsl-63-204-18-61.benefitplans.org/uploads/1/3/0/6/130620731/130620731.html#2-phenylacetic+acid+methyl+ester

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000586a.bin
7a4a2e4ff3d76c890bdd11b23dee0050dd71f867d3087d65551a3c30c57a68a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x586A 3292 bytes
font_01_sfnt_off0000635f.bin
c588c03d42abcbc600f00af73bc53e29904e56ffe39e880b4580b71146d76b9e
pdf-font-stream PDF embedded font (sfnt) at offset 0x635F 5632 bytes
font_02_sfnt_off00007858.bin
8b1231dd2a0c5874a6699133e77e260534e857fd7df68e09134c401faa4b3e23
pdf-font-stream PDF embedded font (sfnt) at offset 0x7858 9140 bytes