Malicious PDF — malware analysis report

Static analysis result for SHA-256 a993f22a3285b849…

MALICIOUS

PDF

41.8 KB Authoring application: Nitro PDF
MD5: c80ca2807a7c34ced1505f5edd8c0586 SHA-1: 7f3695e406e9eb7beafe38ae293aff4e644cd9de SHA-256: a993f22a3285b8494aaa8eae0e59dd279e2cb7ad2af9de55b7c88e90f2aa4a57
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various domains, each hosting a PDF file with a numeric or book-like slug in the URL. This pattern is indicative of a link farm or SEO manipulation tactic, potentially used to distribute malicious content or engage in phishing. The ClamAV detection and ML classifier further support the malicious nature of the file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://adrianaanderson.net/uploads/1/3/0/6/130620619/2454908.pdf
    • http://mx.nwrpdp.com/uploads/1/3/0/6/130621669/7363722.pdf
    • http://norgrenairregulators.com/uploads/1/3/0/6/130621351/kikabolon.pdf
    • http://ajvincentproductions.com/uploads/1/3/0/2/130287311/8537131.pdf
    • http://mpaclarke.com/uploads/1/3/0/3/130379218/7368878.pdf
    • http://cuppagusto.com/uploads/1/3/0/3/130313063/momuvovusulutuwiwav.pdf
    • http://nevenann.com/uploads/1/3/0/5/130539165/1985326.pdf
    • http://swcfamilyretreats.com/uploads/1/3/0/6/130605161/pokamufu.pdf
    • http://aftermarketupgrades.org/uploads/1/3/0/6/130604524/03cf8f.pdf
    • http://safeketozone.com/uploads/1/3/0/5/130544321/5c4057dab9742.pdf
    • http://10122006.com/uploads/1/3/0/7/130738511/penubo.pdf
    • http://artmat.net/uploads/1/3/0/6/130621591/venamugobibutig_luxopifegala_lesetewewas.pdf
    • http://utwatch.org/uploads/1/3/0/6/130605421/9bcf09f9f66.pdf
    • http://care-assn.info/uploads/1/3/0/7/130739504/3120594.pdf
    • http://drewgrahamart.com/uploads/1/3/0/3/130379145/nurupo_bokunipe_rakasinupizet.pdf
    • http://reedhendersontrust.org/uploads/1/3/0/5/130588277/nixigipatikares-rezetoluse-sinidubegedorom.pdf
    • http://bobbodagreen.com/uploads/1/3/0/4/130483810/ed95e1275bb7a42.pdf
    • http://iglesiadiosesreal.net/uploads/1/3/0/2/130289453/1328b53f.pdf
    • http://collabassist.com/uploads/1/3/0/5/130539728/sugat.pdf
    • http://bbeboutiquellc.com/uploads/1/3/0/4/130476423/kiwukinosipob.pdf
    • http://allisongiessuebelhair.com/uploads/1/3/0/6/130605162/pojijiwosifega.pdf
    • http://dfpinvestments.com/uploads/1/3/0/4/130489248/cc545a09463c.pdf
    • http://z.ag/uploads/1/3/0/5/130588540/be6ced.pdf
    • http://morganwaisner.com/uploads/1/3/0/3/130323794/namuwofufavagujijuvi.pdf
    • http://x0568707xstreamtravel.xsideas.com/uploads/1/3/0/7/130776338/130776338.html#acca+p2+past+papers+september+2017

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000032a9.bin
b3b238fd3ac8794d753ddbfa4f07e4c45303c142b604be13bf8677e74c85e3cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x32A9 1960 bytes
font_01_sfnt_off00003df6.bin
f6979505fb43e6a8794f450886bbee53e16ffa02ea885fa0038bc70e259ce6f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x3DF6 8508 bytes