Malicious PDF — malware analysis report

Static analysis result for SHA-256 af99bc3768953c14…

MALICIOUS

PDF

40.4 KB Authoring application: QPDF
MD5: 54d0a3b77bacaf4eb9a8d6efafe2b7c4 SHA-1: 1f56d7371722de41630c2381f334bfa34cbe8737 SHA-256: af99bc3768953c148165685edd04ba1e92055bed9d0c31109ac4d9111646af30
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection also flags this as a phishing-related threat. The embedded URLs point to various domains, suggesting a link farm designed to distribute malicious content or conduct phishing operations. No scripts were extracted, and the document body content is largely obfuscated and contains references to the external URLs.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://micropapillarybreastcancer.org/uploads/1/3/0/6/130621592/898301c078392d.pdf
    • http://afsanehkhoramshahi.com/uploads/1/3/0/5/130589122/cde98e2f0746.pdf
    • http://longhorncaverns.org/uploads/1/3/0/6/130620471/mimixavi.pdf
    • http://precariouslypossible.net/uploads/1/3/0/4/130489253/559f8f8000a8.pdf
    • http://concordlawncareservices.com/uploads/1/3/0/5/130544138/8705763.pdf
    • http://mrspapa.weebly.com/uploads/1/3/0/5/130551749/zabew-wivokiw-ganosomu.pdf
    • http://ne-surgerycenter.net/uploads/1/3/0/6/130621601/130621601.html#simple+compound+and+complex+sentences+worksheet+quiz

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011a6.bin
815f9a3e387fe69adf92f418532b28a3cb38c2dda1ea0a07bb124303b6a9f12b
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A6 8836 bytes
font_01_sfnt_off00005797.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x5797 16036 bytes