Malicious PDF — malware analysis report

Static analysis result for SHA-256 a480f0f2abbfa00e…

MALICIOUS

PDF

40.6 KB Authoring application: Smallpdf Desktop
MD5: 832e348b9a471c3be533d34c361ea6e3 SHA-1: 1be8c6cdbc50af74521f8f19468ae8676519b28a SHA-256: a480f0f2abbfa00e339e77f09997eac8f579489b3fe0a40f0712e583ef5513af
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The ClamAV detection as Pdf.Phishing.TtraffRobotInstall-7605656-0 further supports a phishing or malicious redirection intent. The embedded URLs and the heuristic strongly suggest the document's purpose is to redirect users to potentially harmful websites, likely for phishing or malware distribution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lisixum.clearcaptioner.tech/uploads/2020/01/28/taxilubewemoto.pdf
    • http://fix.buket99.com/uploads/2020/01/29/xiwiw_wufenu_kegobo.pdf
    • http://paddleboardz.com/uploads/1/3/0/5/130588681/xewiwe.pdf
    • http://michaelshusko.com/uploads/1/3/0/4/130476045/130476045.html#aerosmith+dream+on+meme

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000100d.bin
6a269499bf32c58fed159c76ce3482019f1294e2ccbedcc2487492cc21125823
pdf-font-stream PDF embedded font (sfnt) at offset 0x100D 8788 bytes
font_01_sfnt_off00004e42.bin
378288d3133907284a1dd708aec606fa45674349f7e67e9eaedc79a8f6af9139
pdf-font-stream PDF embedded font (sfnt) at offset 0x4E42 16228 bytes
font_02_sfnt_off00006356.bin
50224c6c483bfa86a10f62efd7baa2c756f8036c0a911ebd537387e21b2fb6f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6356 2732 bytes