Malicious PDF — malware analysis report

Static analysis result for SHA-256 b3148955ea354d14…

MALICIOUS

PDF

33.7 KB Authoring application: Mobipocket Creator First seen: 2020-09-24
MD5: 8c88d3c89187f881d498b4efd2f135f9 SHA-1: bd20adde9bcf4e828870f2969c4d144bda5e1914 SHA-256: b3148955ea354d14687d0d02f8a8e7363a61e0399e1944c10c7cad209dfe1e99
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV detection strongly suggest malicious intent, specifically related to phishing or traffic redirection. While no scripts were explicitly extracted, the structure and embedded URLs point towards a malicious document designed to lead users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://polksoccerfund.com/uploads/1/3/0/5/130551125/4383611.pdf In PDF document text
    • http://my-credential.com/uploads/1/3/0/6/130620510/gukurelo.pdfIn PDF document text
    • http://chunchorecords.com/uploads/1/3/0/2/130270872/warenopitifokod-xuden-bimebadajulil.pdfIn PDF document text
    • http://trickhorse.net/uploads/1/3/0/6/130604650/c45a320f64.pdfIn PDF document text
    • http://michaelgierl.com/uploads/1/3/0/4/130436236/702632.pdfIn PDF document text
    • http://northwestuu.com/uploads/1/3/0/5/130542968/130542968.html#bagong+simula+musicIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000102a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x102A 7820 bytes
SHA-256: da3cde1cd5845b8eafed64e5c6a737dd01d8a67523a3e8c1b71f656a6f8b39da
font_01_sfnt_off00003b28.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3B28 16228 bytes
SHA-256: 378288d3133907284a1dd708aec606fa45674349f7e67e9eaedc79a8f6af9139