Malicious PDF — malware analysis report

Static analysis result for SHA-256 c87f15e217c291b9…

MALICIOUS

PDF

85.3 KB Authoring application: PDFedit
MD5: 626cc34001da9f9a39d6d3ad30cc39da SHA-1: a48fb5fec8b59e33cc6741bbf7db6b0bd6245455 SHA-256: c87f15e217c291b91e72bcb9eab81838c643822b616fc713bbd976477402cf8a
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF file contains embedded JavaScript and a large number of external links, indicative of a phishing or SEO manipulation scheme. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a malicious classification. The embedded JavaScript likely facilitates the redirection or exploitation associated with these links.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://villasdiamante.com.mx/uploads/1/3/0/4/130435633/3954752.pdf
    • http://noahsteinman.com/uploads/1/3/0/5/130551390/9667472.pdf
    • http://notariasociati.com/uploads/1/3/0/4/130476130/tafonoluvudajul.pdf
    • http://soulstarmassage.com/uploads/1/3/0/5/130542924/sofomikif.pdf
    • http://cordivanoapparel.com/uploads/1/3/0/4/130489997/eb6e89891bae.pdf
    • http://apslabgroup.com/uploads/1/3/0/5/130550891/geputizexeverimatan.pdf
    • http://jgregoryfilms.com/uploads/1/3/0/5/130590637/lewoxexixakuxilimeg.pdf
    • http://neurodesignlab.com/uploads/1/3/0/5/130539657/mavoledogekerem.pdf
    • http://nicolegoodrich.com/uploads/1/3/0/6/130604511/kusil_vivudagug_guviket.pdf
    • http://newrichmondoh.org/uploads/1/3/0/5/130551585/woroko.pdf
    • http://newperspectivemedical.com/uploads/1/3/0/6/130621838/130621838.html#indian+constitution+in+tamil+language+pdf

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001326.bin
f2f18ad66887bdf220f3bace6e8dacef453f493fabeb5f9a506be9716b7f5e02
pdf-font-stream PDF embedded font (sfnt) at offset 0x1326 8976 bytes
font_01_sfnt_off0000d3fe.bin
32ce164c05324d7d1be08cbc5687d2337e9ec2e6e7252380227489a1354c6e8d
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3FE 10560 bytes
font_02_sfnt_off0000f190.bin
a6498869764dede0fa60b9d47b7ecbd6b491b4c92cdf4f623c1f432b8a570179
pdf-font-stream PDF embedded font (sfnt) at offset 0xF190 17312 bytes