Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fad5ae733e38a0e…

MALICIOUS

PDF

47.8 KB Authoring application: Inkscape
MD5: 37709e425d8ae86df8cd16fe092cca69 SHA-1: e50e97c27b35a844968db4eff33204a0ae028aca SHA-256: 9fad5ae733e38a0ee909303ba03a7394689155ece9b5f080b9c05bfe9a02ae1d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV detection strongly suggest malicious intent. The document body itself is largely unreadable but contains some of the same URLs found in the heuristics, reinforcing the link farm attack pattern. The primary goal appears to be directing users to a network of malicious URLs, likely for phishing or to serve further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bunetili.oracul.pro/uploads/2020/01/27/202508.pdf
    • http://oakcreekcenter.org/uploads/1/3/0/6/130620549/numixi.pdf
    • http://fisonu.cityglush9.icu/uploads/2020/01/27/sunizajelixox_jaxivonuzufina_dobuwajozij.pdf
    • https://lugopebozit.weebly.com/uploads/1/3/0/6/130603744/xumel.pdf
    • https://gutepaga.weebly.com/uploads/1/3/0/3/130313466/b7c1f79fb20061.pdf
    • http://tiwozamel.marketing-digital.ru/uploads/2020/01/28/53cfc7b5f.pdf
    • http://lousbar.com/uploads/1/3/0/3/130379352/57f920.pdf
    • http://juzis.ip-i.ru/uploads/2020/01/27/wimobolu.pdf
    • https://nasazutebil.weebly.com/uploads/1/3/0/5/130589312/doridavubur.pdf
    • https://pikeguxi.weebly.com/uploads/1/3/0/5/130588503/77419ae7b52d4b.pdf
    • http://fitav.yusufkalayci.com/uploads/2020/01/29/4766881.pdf
    • http://xidobaviv.studio-elephant.ru/uploads/2020/01/29/xemexipewawapi.pdf
    • https://fodufixetok.weebly.com/uploads/1/3/0/5/130590478/wovuwidaxu_rifijusepebu_guxebeba.pdf
    • http://cgt-capgemini-ts.net/uploads/2020/01/28/kirorexavapo_zabazebetada_jarevuxufu.pdf
    • https://xafuvoja.weebly.com/uploads/1/3/0/5/130542758/zosepugamojono.pdf
    • http://xarido.comparatuapuesta.com/uploads/2020/01/28/xibuzonuv_lavomamamuzib_rolelomuji_doratorekobu.pdf
    • http://ninktat.com/uploads/1/3/0/5/130590738/lelavexajuxirufexel.pdf
    • http://kenbugulfilm.com/uploads/1/3/0/5/130544754/laxuvipegu.pdf
    • http://las.rantjeteam.ru/uploads/2020/01/27/dajono_visusefa.pdf
    • https://timajonar.weebly.com/uploads/1/3/0/3/130323952/gogurafup_petofofazexabuk.pdf
    • http://wedid.ru/uploads/2020/01/27/cac32eeff90bb7.pdf
    • https://wezusazaxep.weebly.com/uploads/1/3/0/4/130483355/c62be002dfa0.pdf
    • http://rejoso.zoomroom63.ru/uploads/2020/01/28/5c7e4ca676f343d.pdf
    • http://blaketedeschi.com/uploads/1/3/0/4/130436354/130436354.html#naruto+can+sing+fanfiction
    • http://rejoso.zoomroom63.ru

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001757.bin
325b29da10ab7903f07c45ef98f5ea6ab1af72e945a8b16ef8622e1d3d0cec9e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1757 9052 bytes
font_01_sfnt_off000071d0.bin
2cdbb021946863abefcea69c147ecba1deb91015bdcbfab198bfb9b45e854878
pdf-font-stream PDF embedded font (sfnt) at offset 0x71D0 16540 bytes