Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a47526778dcc433…

MALICIOUS

PDF

44.9 KB Authoring application: Inkscape
MD5: af5180e5478cf7d2b821bf52badffba9 SHA-1: 56563aef3960b7f93a17bbe5713cf72e840b8f6d SHA-256: 9a47526778dcc4331936d101a75e0f7b8b92b18bb355544f69ebe2898901fdf8
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, suggesting a phishing or malware distribution campaign. The ML classifier and ClamAV detection further support the malicious nature of this file. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://north-shore-aerial-imaging.com/uploads/1/3/0/7/130774973/jofenarevu_masezife.pdf
    • http://hhr.life/uploads/1/3/0/6/130620708/gujazezutar_mavujojidarax_rinazoje_pebijul.pdf
    • http://hostmaster.temposhop.co.uk/uploads/1/3/0/6/130621947/60308e4.pdf
    • http://thenestbusinessconsulting.com/uploads/1/3/0/6/130640101/9680261.pdf
    • http://persevere-gaston.com/uploads/1/3/0/6/130639263/sejimixo-vusuxewaxakibin-wibetu.pdf
    • http://afterthefallinc.com/uploads/1/3/0/6/130603935/3272987.pdf
    • http://nerdypirate.com/uploads/1/3/0/4/130476944/femazamaneji_vumasamawufuw_buvopefesiwoge_denow.pdf
    • http://westovhell.com/uploads/1/3/0/6/130639646/viwuzaba-tomop-guluwipaxaxuga-bisifizomapunik.pdf
    • http://vantagepointchiro.com/uploads/1/3/0/5/130539241/47f856028ddf.pdf
    • http://mta-sts.classicwoodworksofmi.com/uploads/1/3/0/6/130620746/3fe1156aba.pdf
    • http://bangkokplasticsurgery.net/uploads/1/3/0/7/130775304/1204099.pdf
    • http://arthurdogsontodd.com/uploads/1/3/0/4/130483993/8933293.pdf
    • http://griwines.com/uploads/1/3/0/4/130436188/gimev_mamekutigeg_renokanoda_bubituri.pdf
    • http://weavetastic.com/uploads/1/3/0/8/130815437/rarum-fupogutomar-refik.pdf
    • http://teamclm.com/uploads/1/3/0/6/130639922/130639922.html#acetyl-coa+carboxylase+activity

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000481c.bin
4d9ec2aec8f1ca6bebe1b56492fd55a77bba3a6e98efb76508c1b835d4eb9912
pdf-font-stream PDF embedded font (sfnt) at offset 0x481C 2860 bytes
font_01_sfnt_off00005507.bin
a777994f63a68a9fe0a0938aa4a361af1797e30893b73f5b75ef005563f79189
pdf-font-stream PDF embedded font (sfnt) at offset 0x5507 8776 bytes