Malicious PDF — malware analysis report

Static analysis result for SHA-256 9bc44c30c82dddd1…

MALICIOUS

PDF

36.7 KB Authoring application: OpenOffice.org
MD5: be6f7f88d8000006abcc573786cbc727 SHA-1: c9c7ce1dd68a37ffb0709256903b2638b1be5524 SHA-256: 9bc44c30c82dddd1c2484351d9d0b98e45fd650a56dc36696cd0e7ae8fab5ac5
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to distribute further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body is heavily obfuscated and does not provide clear textual clues, but the heuristic firings are sufficient to determine the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mizfamphoto.com/uploads/1/3/0/4/130476078/xojifuduwiliw-rawuvuminete-vipodenovimulit.pdf
    • http://clairevaneeghen.com/uploads/1/3/0/4/130436078/vapikutoxilit_ruzuvona_rejesavedejavav_xekiza.pdf
    • http://medcem.org/uploads/1/3/0/6/130604467/sejigovugokenadedig.pdf
    • http://pickorpress.com/uploads/1/3/0/4/130476657/zonuwo.pdf
    • http://imove.today/uploads/1/3/0/6/130639170/9ce4f4780f.pdf
    • http://alliesonthejourney.com/uploads/1/3/0/8/130813403/tozumeteve.pdf
    • http://nwm8.club/uploads/1/3/0/5/130551487/6055999.pdf
    • http://jkdistribution.co.uk/uploads/1/3/0/6/130621841/jegudufegenuk.pdf
    • http://moldalbany.com/uploads/1/3/0/6/130604391/jenatavixaled_goxebamofaj_tuvisel_jebekipil.pdf
    • http://www.luraydwilawyer.net/uploads/1/3/0/5/130589020/1818703.pdf
    • http://eachdayagift.com/uploads/1/3/0/3/130313436/4335689.pdf
    • http://gonzosautotronicdiagnosticcenter.org/uploads/1/3/0/2/130289554/jufuk-takakalosilotu-mataxadetubomiv-mazesovuxevob.pdf
    • http://petervuphotography.com/uploads/1/3/0/7/130776474/c856225bf.pdf
    • http://storyframe.video/uploads/1/3/0/7/130740054/f7f3c3d17868.pdf
    • http://sq6tb.slpny.com/uploads/1/3/0/4/130435672/130435672.html#plant+kingdom+class+11+ncert+tricks
    • http://nwm8.club/uploads/1/3/0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000034dc.bin
9f4898631d40fd89b02a3d9b97dad1f520d3a9f337967581889b120273778d11
pdf-font-stream PDF embedded font (sfnt) at offset 0x34DC 8136 bytes