Malicious PDF — malware analysis report

Static analysis result for SHA-256 acdb5bfaea19cf9f…

MALICIOUS

PDF

40.5 KB Authoring application: Soda PDF
MD5: 29dda16321cb0b40000ac614b4ee47a2 SHA-1: f8356bae49815381218f22f2b30a01365882e748 SHA-256: acdb5bfaea19cf9f8688dd15bfa466badb11932c5413ffee76c44b8b329f7cd4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0 and a machine learning classifier with high confidence. Static analysis revealed a large number of embedded URLs, indicating a link farm likely intended to redirect users to malicious content or for SEO manipulation. The document body contains garbled text, suggesting it is not intended for direct user consumption but rather as a container for the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://emilyburdettphotography.com/uploads/1/3/0/2/130291415/xubikivupufubotuzi.pdf
    • http://rmtdesigngroup.com/uploads/1/3/0/7/130738996/da160.pdf
    • http://cottinghamhuntingclub.com/uploads/1/3/0/7/130776106/zazow.pdf
    • http://traprockpottery.com/uploads/1/3/0/6/130604018/vaxifafud.pdf
    • http://advokat-moscow24.site/uploads/1/3/0/7/130776514/8670730.pdf
    • http://mail.mindfuldoodles.com/uploads/1/3/0/4/130476318/barimakoli-moguruvove-logor.pdf
    • http://retreatinsider.com/uploads/1/3/0/4/130475964/xapirogumagi.pdf
    • http://slushproductions.com/uploads/1/3/0/7/130739268/sepifix.pdf
    • http://dirtysoles305.com/uploads/1/3/0/4/130483232/2b94400c.pdf
    • http://stylebyquilo.com/uploads/1/3/0/6/130639315/pobowuzaliber.pdf
    • http://upcyclemom.com/uploads/1/3/0/6/130603976/fc43056c38.pdf
    • http://insciteillinois.org/uploads/1/3/0/8/130814992/f1a06358734f0.pdf
    • http://www.lacysphotos.com/uploads/1/3/0/3/130323513/lelazozasuf-pugovigil.pdf
    • http://casagallegaavenidas.com/uploads/1/3/0/3/130323277/nesigi.pdf
    • http://kubertradingcompany.com/uploads/1/3/0/4/130476102/5782a3.pdf
    • http://rifugiovallegrande.store/uploads/1/3/0/6/130621194/pelulipizixuxojugat.pdf
    • http://vegancannabis.com/uploads/1/3/0/8/130813860/4296696.pdf
    • http://insideosuokc.net/uploads/1/3/0/6/130640097/0a910bf6.pdf
    • http://kfz-kirschen.com/uploads/1/3/0/2/130273894/vakixujedixado.pdf
    • http://www.mpdesigns.studio/uploads/1/3/0/7/130775705/6031017.pdf
    • http://myautosaver.com/uploads/1/3/0/2/130288448/mewasi_lulimaze_nizemonukagomu.pdf
    • http://drfranklinlevin.com/uploads/1/3/0/2/130272072/cd718e421c4d26.pdf
    • http://myanmarlogisticsolutions.com/uploads/1/3/0/7/130775321/pezagozaz.pdf
    • http://llnoble.net/uploads/1/3/0/6/130604700/6df7a531e3.pdf
    • http://www.fearlesssocial.net/uploads/1/3/0/2/130270790/130270790.html#low+back+pain+treatment+exercise
    • http://myanmarlogist

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f91.bin
0494931b1f6841e954f1dd319798c9a2e4f1bb87bbed3e4da94cbc7d98b328d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F91 2176 bytes
font_01_sfnt_off00003bde.bin
ecdf0652e3ccf2b29663f08b0c5c23b91bf78bab3375b863571e1d1c79455c58
pdf-font-stream PDF embedded font (sfnt) at offset 0x3BDE 7464 bytes