Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d34808062ba002c…

MALICIOUS

PDF

49.7 KB Authoring application: Smallpdf Desktop
MD5: d54739f6d885990e97b3beb94ed09ea1 SHA-1: 7bb7c96eede169e2cb7f69ffbd55e276c644b9ee SHA-256: 9d34808062ba002cbe8d01198de29d6d3e94db5ff229df12860182f3c25eafd7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, a technique commonly used for SEO poisoning or to redirect users to malicious websites. ClamAV identified this as Pdf.Phishing.TtraffRobotInstall-7605656-0, and ML classification strongly supports maliciousness. The document body is heavily obfuscated and unreadable, providing no direct clues to the lure. The primary attack vector appears to be the mass of links pointing to various domains, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://onegroupair.com/uploads/1/3/0/4/130476766/5b3a1c4.pdf
    • http://fallingcinders.shop/uploads/1/3/0/5/130588484/bd8b3a6aa9d152.pdf
    • http://novasnow.store/uploads/1/3/0/7/130775851/1551863.pdf
    • http://clairebaconagility.com/uploads/1/3/0/6/130605312/latibu_gegarifese.pdf
    • http://nitrolife.me/uploads/1/3/0/6/130621932/6148515.pdf
    • http://otownpyle.com/uploads/1/3/0/7/130739363/puvamogezewuze_famawusawafuza_gefejuniwi_guwijawomes.pdf
    • http://davidcasillas.com/uploads/1/3/0/6/130620632/wajufafafiv.pdf
    • http://splinteredmindprints.com/uploads/1/3/0/5/130539102/zujozode.pdf
    • http://mydentalpartner.com/uploads/1/3/0/7/130739287/73ed82c0b25c.pdf
    • http://www.daniellawsn.com/uploads/1/3/0/3/130379222/maxalevuzet-lebumigufibuv.pdf
    • http://hauntedpaintball.com/uploads/1/3/0/6/130604270/karefifuwimakaw.pdf
    • http://nationalbrainhealth.org/uploads/1/3/0/4/130483202/274676.pdf
    • http://mirrorimagemissions.com/uploads/1/3/0/5/130545333/giwesarexamadezuv.pdf
    • http://redpocket.com.au/uploads/1/3/0/6/130605153/nurenajumo_pagosud_sojazodum_liwurasiwozefi.pdf
    • http://hostmaster.biotop-naturkostmarkt.de/uploads/1/3/0/7/130776724/3626879.pdf
    • http://bagsofun.co.uk/uploads/1/3/0/2/130271245/bitutunu_luwawimav_semowod.pdf
    • http://shop.lewisinteriors.com/uploads/1/3/0/6/130639175/4991914.pdf
    • http://caskmutation.org/uploads/1/3/0/6/130640183/8606824.pdf
    • http://trustwaived.com/uploads/1/3/0/2/130272644/zumesiwatutefak.pdf
    • http://connectingmoments.co.nz/uploads/1/3/0/7/130775087/3996847.pdf
    • http://kadrome.site/uploads/1/3/0/3/130379231/3753570.pdf
    • http://ryanstead.com/uploads/1/3/0/6/130620173/xusigutewobug.pdf
    • http://live4todayusa.org/uploads/1/3/0/3/130379218/130379218.html#accounting+education+an+international+journal+impact+factor

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001175.bin
f69cef93dba8faf922d2b744b2933d16a7bbb5e4847979bc5395d089f4c475bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1175 9400 bytes