Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc843bcaf8a75fae…

MALICIOUS

PDF

37.4 KB Authoring application: Adobe PDF Library 9.0
MD5: 0e68c7d4540224a4af5ad648ec7b4092 SHA-1: b7968267896fc08873d2d11776d86a44c4a3aac5 SHA-256: cc843bcaf8a75faea7e3d35ef78019e0af13e1dcf68ed9ed6b132aee45f715d0
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files hosted on various domains. This behavior is indicative of a link farm or redirection scheme, likely intended to lead users to malicious content or phishing pages. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic redirection intent. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://noworries-caretakers.com/uploads/1/3/0/6/130639054/9223168.pdf
    • http://attorneyspacesharing.com/uploads/1/3/0/3/130323445/negoviteb-gosugoximudegut.pdf
    • http://1169certified.org/uploads/1/3/0/5/130551126/2245890.pdf
    • http://mirkamalmi.com/uploads/1/3/0/5/130550936/a7f52befd4f8.pdf
    • http://homecyberprotect.com/uploads/1/3/0/5/130588318/gopozegubivamuvesed.pdf
    • http://consultoriasrojas.com/uploads/1/3/0/6/130603761/1211931.pdf
    • http://woodlandharvestmountainfarm.org/uploads/1/3/0/6/130620163/sijufevipa_punadivonib_saruvabibi_mukigowukuze.pdf
    • http://succeed2serve.com/uploads/1/3/0/7/130739938/7396338.pdf
    • http://agentlemansartwork.com/uploads/1/3/0/5/130540065/giranigenesov_kivoxaga_pimekewuw_pifijivif.pdf
    • http://vancouvervideopro.com/uploads/1/3/0/6/130622023/8726225.pdf
    • http://nutrition-doctor.co.uk/uploads/1/3/0/6/130639653/130639653.html#australian+gaap+vs+ifrs+pwc

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012a5.bin
020c1079f61789ed752ed59d2905a47339c40a60c30fd57a135530588c08a665
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A5 7812 bytes