Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4a06671d444535f…

MALICIOUS

PDF

34.6 KB Authoring application: Karbon
MD5: 9f8c0c9bad24e0f6c8d8734c41d80ab5 SHA-1: e64befdceb2b6f020d4ede1c6278fd6bafe6e23c SHA-256: c4a06671d444535f8d08586bc6162d14b6db54d0e18a87ffd3af44577f7766a8
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by multiple heuristics, including ClamAV and an ML classifier, for malicious content. The PDF_SEO_LINK_FARM heuristic specifically identified a large number of external links, with the first being http://mrjohnmiddleton.com/uploads/1/3/0/5/130551671/girovobaf.pdf. This indicates a likely phishing or malware distribution attempt through a link farm strategy.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mrjohnmiddleton.com/uploads/1/3/0/5/130551671/girovobaf.pdf
    • http://newyoujewelryshop.com/uploads/1/3/0/3/130313127/5314062.pdf
    • http://1-to-6.com/uploads/1/3/0/5/130589208/4882388.pdf
    • http://782hustle.com/uploads/1/3/0/2/130271229/dorifegiz.pdf
    • http://myberrygoodlife.com/uploads/1/3/0/4/130483928/130483928.html#grand+cherokee+manual+transmission+s

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001018.bin
926491146e811eb7f9f8a3186890820fc3a83325d15b29a9563c84a63c47dede
pdf-font-stream PDF embedded font (sfnt) at offset 0x1018 8344 bytes