Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e5939564d772df6…

MALICIOUS

PDF

43.8 KB Authoring application: PDFedit
MD5: 818098c2e6f34fa0968ed4477b784933 SHA-1: 6481c1e4d9475e89bbcdd8dfeb1f89f30c64d77a SHA-256: 9e5939564d772df6f6c7e79c1f693e653097662cb8feb0188b9fd33de07c5cce
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or phishing attempt. The SE_INVOICE_LURE heuristic indicates the document may be disguised as an invoice or payment request. The ClamAV detection further confirms its malicious nature. The primary attack pattern involves luring the user to click on one of the numerous embedded URLs, which likely lead to malicious content.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://contact.dng.ie/uploads/1/3/0/3/130379293/lenefi.pdf
    • http://sleepoutlouies.com/uploads/1/3/0/6/130621771/9241555.pdf
    • http://alpinetransportationgroup.com/uploads/1/3/0/3/130313405/pixexozi.pdf
    • http://northeastflowershop.com/uploads/1/3/0/2/130271073/8ed2078.pdf
    • http://binarybotreviews.com/uploads/1/3/0/5/130539059/goxivosis-gonir-panoditabarevux.pdf
    • http://noridirg.com/uploads/1/3/0/5/130589371/digakobobexabutafu.pdf
    • http://wileybrands.com/uploads/1/3/0/6/130639309/adcd59f3521abb.pdf
    • http://connectionuniverse.co.uk/uploads/1/3/0/6/130621636/lorokubis.pdf
    • http://mrblacksmusic.com/uploads/1/3/0/5/130589090/6f3a4615e7b68.pdf
    • http://www.cindylxy.com/uploads/1/3/0/2/130272102/zesarugijizujipoguw.pdf
    • http://miamiflpressurewashing.com/uploads/1/3/0/3/130313157/pomexakafexigo.pdf
    • http://cordiaaladvies.nl/uploads/1/3/0/4/130483307/xibitusowusil_leravi.pdf
    • http://niumanatreecare.com/uploads/1/3/0/4/130483626/a545609133.pdf
    • http://comptek.us/uploads/1/3/0/4/130476816/gexamaf.pdf
    • http://discountcannadelivery.com/uploads/1/3/0/5/130539840/natoroxesi_gutijises.pdf
    • http://www.joshuaevanslaw.com/uploads/1/3/0/6/130605216/7234546.pdf
    • http://txpublicschoolproud.com/uploads/1/3/0/5/130551971/095bcf.pdf
    • http://newbraunfelsmasonry.com/uploads/1/3/0/8/130814761/9691672.pdf
    • http://piercingsbylexie.com/uploads/1/3/0/4/130435826/3248644.pdf
    • http://hunterbragg.com/uploads/1/3/0/3/130379741/wilorok_losub.pdf
    • http://www.kimerprops.com/uploads/1/3/0/5/130545173/kawaduxasidetop_wuzuduzolopekaw_pinitefo_nipogapelididip.pdf
    • http://kaialynn.com/uploads/1/3/0/7/130775792/130775792.html#revit+lt+and+autocad+lt
    • http://hunterbragg.co

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000031ea.bin
afd8868629b61d85ec32a8a0de1ca84da82d48156cdd7447d7c4f51403cf5149
pdf-font-stream PDF embedded font (sfnt) at offset 0x31EA 5244 bytes
font_01_sfnt_off000045b6.bin
69e9860357dc77a6af3be4a114c97170cd6203f42a46e6716c0d7a4a63289438
pdf-font-stream PDF embedded font (sfnt) at offset 0x45B6 10040 bytes