Malicious PDF — malware analysis report

Static analysis result for SHA-256 b21cf3b8edf50f0a…

MALICIOUS

PDF

44.6 KB Authoring application: PDFedit
MD5: 30080cd27b3e3b2b87f906e1c96b67d2 SHA-1: 28bcc1f4a6b165500b62892532af0f73c3b47865 SHA-256: b21cf3b8edf50f0a0a86fa14fc44f7708653d4f9eda7ae1c46fc03d3ad52f452
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by multiple heuristics, including a critical finding for a link farm and ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The embedded URLs suggest a phishing or malicious content distribution scheme, likely aiming to redirect users to further malicious PDFs. The document body contained garbled text, providing no additional context for the attack's pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nanascountryporch.com/uploads/1/3/0/6/130621124/setovuvuvejezesig.pdf
    • http://7-niebo.com/uploads/1/3/0/6/130620228/wubinawaxisekaj.pdf
    • http://www.fixyourclassic.co.uk/uploads/1/3/0/2/130271063/850ead21a0f6.pdf
    • http://shineupandrise.com/uploads/1/3/0/6/130604056/4309105.pdf
    • http://rmheffects.com/uploads/1/3/0/4/130476318/detapamif.pdf
    • http://rickformi.net/uploads/1/3/0/5/130588635/1954077.pdf
    • http://openpaw.net/uploads/1/3/0/2/130272071/ruwinesileg.pdf
    • http://jolenesphotography.com/uploads/1/3/0/2/130287514/dcf405b.pdf
    • http://ellestewart.com/uploads/1/3/0/6/130639407/rabakan.pdf
    • http://docksideengraving.com/uploads/1/3/0/8/130813953/2cdb418bc.pdf
    • http://atlkickball.com/uploads/1/3/0/2/130272282/9042351.pdf
    • http://showcasehomepainting.com/uploads/1/3/0/2/130287915/bitora-nedalusazilefas-rodomomemowovem-nawidakijakaj.pdf
    • http://hackatx.info/uploads/1/3/0/7/130775902/8865a4238a4c.pdf
    • http://rockymountainhighimages.com/uploads/1/3/0/8/130814032/wimepatim-petowuse-rilagonemisuta.pdf
    • http://thingraniteveneer.com/uploads/1/3/0/6/130620778/502749.pdf
    • http://peireptileexpo.ca/uploads/1/3/0/6/130621700/df5e0f98b989b7a.pdf
    • http://t24player.live/uploads/1/3/0/5/130588763/209cdc1.pdf
    • http://salaamboston.com/uploads/1/3/0/5/130540290/6631733.pdf
    • http://norshus.com/uploads/1/3/0/5/130588286/4348080.pdf
    • http://tateglass.com/uploads/1/3/0/2/130291352/figidafezibinon.pdf
    • http://ctmelectricinc.com/uploads/1/3/0/8/130814675/lowufukilavuvop.pdf
    • http://mercedes.fit/uploads/1/3/0/6/130621483/lepojudodezimux_matifujuna_rixiboka_nujalinabetiri.pdf
    • http://omc4thgrade.com/uploads/1/3/0/6/130621798/zoxituvobisumew.pdf
    • http://taleinthetail.com/uploads/1/3/0/8/130814232/130814232.html#html+table+with+rowspan+and+colspan+example
    • http://ellestewart.com/up
    • http://ptc.company.com/uploads/1/3/0/3/130379363/farugimizega_memifuvuxanozim_wetujujazasume_mikogekiborax.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000033ac.bin
f592bba58cad1c13646b17c345e5fdaf76a301b5a950b88a8b0c784fdf8afbd2
pdf-font-stream PDF embedded font (sfnt) at offset 0x33AC 8928 bytes
font_01_sfnt_off00005197.bin
0c8b636322dcb4d69dd08a763b09c4b5ff2b7ea73056f43add13012560a79e6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x5197 16076 bytes