Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dd3bf55e8d15e4f…

MALICIOUS

PDF

43.0 KB Authoring application: PDFBox
MD5: 511ea8a42ca3f4d72be8f63a2b9e10ea SHA-1: 6080ebae3f2fd55619d85aade818b1f5c9857365 SHA-256: 9dd3bf55e8d15e4f3f5cd7f6d0254c2c07110bb60d0b51b9d6c3170c0948bb57
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or redirection mechanism. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic-driving intent. The document body contains garbled text and references to 'PDFBox' and 'Ejercicios de adjetivos comparativos y superlativos en ingles online', which appear to be decoys or part of the obfuscation.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://processworkboston.com/uploads/1/3/0/5/130544687/tipajo.pdf
    • http://horacekingston.com/uploads/1/3/0/6/130639321/8125705.pdf
    • http://krgservicecorp.com/uploads/1/3/0/7/130776252/wodalepatu.pdf
    • http://mindfulohio.com/uploads/1/3/0/6/130639318/ruposo_pirasox_xojejunapukuxo.pdf
    • http://makeyourmark.shop/uploads/1/3/0/5/130590541/3137359.pdf
    • http://hotelvic-phase2-zh.devsite-1.com/uploads/1/3/0/4/130489933/9287561.pdf
    • http://aatpros.com/uploads/1/3/0/5/130588225/rebovutivape_fezivenafogebur.pdf
    • http://bloomboxenergy.us/uploads/1/3/0/6/130639215/tapexigibitu_tuxofokopi.pdf
    • http://www.agoodtalker.com/uploads/1/3/0/5/130588714/eade70dc8fec4.pdf
    • http://amarbeck.com/uploads/1/3/0/6/130605355/renewegazo.pdf
    • http://nandaphoto.com/uploads/1/3/0/6/130639528/kowojapuf.pdf
    • http://bubblegumfantasies.com/uploads/1/3/0/3/130379445/7483544.pdf
    • http://pantyhosenow.com/uploads/1/3/0/3/130379818/f43742f5.pdf
    • http://quirkydogartwork.com/uploads/1/3/0/5/130588830/5027465.pdf
    • http://www.doggedwriting.com/uploads/1/3/0/7/130738482/xurazelatasodiv.pdf
    • http://ohayocleaning.com/uploads/1/3/0/2/130289335/5933959.pdf
    • http://thecooklife.com/uploads/1/3/0/4/130435659/3325570.pdf
    • http://lunchmatrix.com/uploads/1/3/0/8/130874139/1b7b63e7.pdf
    • http://mezohenley.co.uk/uploads/1/3/0/6/130603842/2321882.pdf
    • http://rhiagowen.net/uploads/1/3/0/7/130738825/riribe.pdf
    • http://bethwrightdesigns.com/uploads/1/3/0/6/130603692/619bf.pdf
    • http://menagainstcancer.net/uploads/1/3/0/8/130814382/juruf.pdf
    • http://communityspanish.com/uploads/1/3/0/5/130551126/d2e632.pdf
    • http://myholisticskinclinic.com/uploads/1/3/0/5/130540037/6775930.pdf
    • http://theredgal.com/uploads/1/3/0/9/130969760/130969760.html#ejercicios+de+adjetivos+comparativos+y+superlativos+en+ingles+online
    • http://bloomboxenergy.us/upload

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002d3d.bin
f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D3D 16204 bytes
font_01_sfnt_off00004547.bin
c9577f5e5d864ff99719a1fc40302b6214c5c8c1438c10631f12520e5c4cb7fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x4547 8336 bytes