Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa1ba0075cdaecf7…

MALICIOUS

PDF

37.0 KB Authoring application: Serif PagePlus
MD5: 7dd9bd693bb00b7b58ae7c9c60a0f9ac SHA-1: 20017184f7d2eb52524a06402f0e1bc811359932 SHA-256: aa1ba0075cdaecf7ac6f32e81fb22b7214b0e47d736036f20c7ece98138c1c41
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection as Pdf.Phishing.TtraffRobotInstall-7605656-0 further indicates malicious intent. The document body, though partially corrupted, contains text related to Achilles tendinitis, which may serve as a lure. The primary attack pattern involves directing users to a vast network of external PDF files, likely for SEO poisoning or to host further malicious content.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://alyecollection.com/uploads/1/3/0/2/130273790/rivovi_gevog.pdf
    • http://carlyberg.com/uploads/1/3/0/6/130604838/vugefosu.pdf
    • http://koesterpraktijk.weebly.com/uploads/1/3/0/3/130379181/poterisexa-jijut.pdf
    • http://glencoveestates.com/uploads/1/3/0/6/130639583/rijimopizoris-dexupapaxanas-lumidejawe.pdf
    • http://billoberlander.com/uploads/1/3/0/7/130740133/836dc817f8a5e.pdf
    • http://mercertruckaccessories.ca/uploads/1/3/0/3/130379676/7827026.pdf
    • http://akihiroyasui.com/uploads/1/3/0/5/130588798/4899731.pdf
    • http://tenafix.cejusthepron.com/uploads/2020/01/29/rowazexiralad-goxoz-bamaborap-rulofapuda.pdf
    • http://pinotnoiro.com/uploads/1/3/0/4/130436058/gosonivobizegofalezo.pdf
    • http://europeanclayroofing.com/uploads/1/3/0/7/130740573/c3ef63e.pdf
    • http://blitzthetraffickers.com/uploads/1/3/0/4/130477309/deser-larexitijoz.pdf
    • http://beachhousedestin.net/uploads/1/3/0/6/130604290/jaloxar_lomur_kelesabonerinu.pdf
    • http://daisykim.com/uploads/1/3/0/8/130874451/ec8fa3ef6f14.pdf
    • http://summaarquirectura.com/uploads/1/3/0/2/130271224/f58f373c81a.pdf
    • http://alumark-gerueste.de/uploads/1/3/0/5/130589318/4053824.pdf
    • http://tanilaba.orlylogistics.com/uploads/2020/01/28/210c855bede71c.pdf
    • http://619756869709789420.com/uploads/1/3/0/6/130604299/4139ef.pdf
    • http://mirrorimagedanceteam.com/uploads/1/3/0/3/130323596/3719007.pdf
    • http://restaurantelallorona.com/uploads/1/3/0/5/130542831/mubivixejekuf.pdf
    • http://autismbroadband.com/uploads/1/3/0/3/130323612/kujora_wotakezadavu_nevuro.pdf
    • http://abidinghopeinstitute.org/uploads/1/3/0/7/130739811/posazo-gadevosudidegu-sutofaxe-memelev.pdf
    • http://muchnesslife.com/uploads/1/3/0/2/130291416/5819003.pdf
    • http://mhrandlenovels.com/uploads/1/3/0/6/130621132/130621132.html#achilles+tendinitis+no+heel+pain
    • http://autismbroadband.com/uploads/1/3/0/3/130323612/kujora_wota

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ee9.bin
87208e3f3648a07839070d4f0fff01b848675677c48a46930d968be4bceace57
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EE9 7856 bytes