Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3986d60ebf0f743…

MALICIOUS

PDF

38.3 KB Authoring application: LibreOffice Draw
MD5: 6abb44d8ac9d0212638b237ac7f66541 SHA-1: 1fa2a6838b60195327f1a3434ae4313b891f0a59 SHA-256: a3986d60ebf0f74313559813502dfd24167382d785c0da6bc98ebb7f4dd857d8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was detected as malicious by ClamAV with the signature Pdf.Phishing.TtraffRobotInstall-7605656-0. Static analysis revealed a large number of embedded external links, indicating a link farm designed to redirect users to potentially malicious content. The primary heuristic firing, PDF_SEO_LINK_FARM, confirms this behavior, highlighting the extensive use of external PDF links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://psykhoshop.com/uploads/1/3/0/5/130541552/7615802.pdf
    • http://rockandrollroadshow.com/uploads/1/3/0/5/130590666/6e77817.pdf
    • http://ihateqatar.org/uploads/1/3/0/5/130540592/saludusapo.pdf
    • http://hostmaster.nyproductions.co.uk/uploads/1/3/0/4/130435582/5918320.pdf
    • http://brentdiggs.info/uploads/1/3/0/5/130589397/xepatu_telelasigo.pdf
    • http://plumeify.fr/uploads/1/3/0/3/130313049/xireg_kasituv_seloseruju_nikirimese.pdf
    • http://mtgcoop.com/uploads/1/3/0/8/130814483/kamibux_daveluwotad_rotivufovuxerif.pdf
    • http://clearorm.com/uploads/1/3/0/7/130739747/70862f2dcb.pdf
    • http://ideageeks.net/uploads/1/3/0/7/130775936/bidefa-zefiwoluxubob-lezupavimuzup.pdf
    • http://a-ive.club/uploads/1/3/0/5/130588921/farasiroja_fibizinerek_kevoxopax.pdf
    • http://barringtonmiddleschoolpto.com/uploads/1/3/0/5/130543488/9475324.pdf
    • http://animals-pro.com/uploads/1/3/0/6/130621160/40ebc.pdf
    • http://innovalprocess.net/uploads/1/3/0/2/130292013/7368920.pdf
    • http://virtual-humans.com/uploads/1/3/0/5/130539241/xufefeniwifip_fikotutilemare_rebofo_lasixilok.pdf
    • http://ncsportsperformance.com/uploads/1/3/0/4/130478819/3cb840baa4e4.pdf
    • http://123chinese.org/uploads/1/3/0/3/130323908/3c98447e466.pdf
    • http://www.streetefam.com/uploads/1/3/0/4/130483407/9f6344662aea.pdf
    • http://winningft.lucky1st.com/uploads/1/3/0/5/130540240/130540240.html#cm+grid+paper+free+printable

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002e46.bin
d907c570f1f8f2d62f38d7529dbf77de46ca3a1917ec53aca7a78bae59874b04
pdf-font-stream PDF embedded font (sfnt) at offset 0x2E46 2616 bytes
font_01_sfnt_off000039ca.bin
4de3cb60521611404aefe323138ff49a39f136e874117bc8e2aeda23fe1f39ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x39CA 7500 bytes