Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce399902fcbdacd6…

MALICIOUS

PDF

39.7 KB Authoring application: OpenOffice.org
MD5: c990fc4bc24dcbd2a30df5ba29c1eed9 SHA-1: 399dd69c7ed8d3592157269b468f43bc88011084 SHA-256: ce399902fcbdacd6c9f34d8bdc3173fb4ae8feeb892b5c11dfa500de5e641220
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to other PDF files. This suggests a link farm or distribution mechanism. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The embedded URLs are the primary IOCs for this threat.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fesel.macronbit.com/uploads/2020/01/29/acb360b5.pdf
    • http://select-tech.shop/uploads/2020/01/28/27982de14e9f.pdf
    • https://vukusabex.weebly.com/uploads/1/3/0/6/130604612/2610971.pdf
    • http://miss-diva.com/uploads/1/3/0/4/130435738/redadonuwi.pdf
    • http://detskepovidky.com/uploads/2020/01/28/nigasula.pdf
    • http://podivexex.validaingresso.com/uploads/2020/01/29/janinawelipupaxar.pdf
    • http://nekimastrategies.com/uploads/1/3/0/6/130603855/vulanekone-mejixaz-divawawive.pdf
    • http://sharonthelibrarian.com/uploads/1/3/0/3/130379147/dc48d9c200cf94b.pdf
    • http://dozuvuwawo.wapfan.ru/uploads/2020/01/28/e16346f5ed829.pdf
    • http://glorydaysmagazine.com/uploads/1/3/0/6/130603975/gunogivivifuna_fufotuta_betonex_fajapo.pdf
    • http://artichokesociety.org/uploads/1/3/0/5/130545333/adfd5cc6d90762.pdf
    • http://thisweekinimmigration.weebly.com/uploads/1/3/0/4/130489275/zawadivukaful-sukilefimesur-kezegozala.pdf
    • http://cureand.com/uploads/1/3/0/5/130550750/1377463.pdf
    • http://mugiton.stroyport.info/uploads/2020/01/29/ae646694c8bf.pdf
    • http://charjormusic.com/uploads/1/3/0/4/130483565/75fe292726f82b5.pdf
    • http://mtziongoshen.church/uploads/1/3/0/5/130588651/d5eb05f0dcc.pdf
    • http://realmsofreflections.com/uploads/1/3/0/5/130551739/vomepugepe.pdf
    • https://buzevogijuxebil.weebly.com/uploads/1/3/0/5/130543134/lejerazobeto_bizuman.pdf
    • http://rostelekomrtk.info/uploads/2020/01/28/toxaxubinapinuk.pdf
    • http://xijokinene.lifeneo.com/uploads/2020/01/28/mekixeluvojuzitagid.pdf
    • http://jomajoguso.nix-dns-oldi.info/uploads/2020/01/27/986f246560.pdf
    • https://jadukekazonabis.weebly.com/uploads/1/3/0/5/130539944/zebalatibekidakuw.pdf
    • http://jesseswarriors.com/uploads/1/3/0/2/130272847/6073806.pdf
    • https://bokizokepotuza.weebly.com/uploads/1/3/0/3/130324351/6692107.pdf
    • http://stephenm.ca/uploads/1/3/0/5/130543878/8103593.pdf
    • http://nationalbusinesseducationweek.com/uploads/1/3/0/4/130476141/130476141.html#beginning+blend+sounds+worksheets

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017c0.bin
d1f16459203ea00682f3b325a71b63a135d5d7cb966dd2f7c7f69fcf4eab0849
pdf-font-stream PDF embedded font (sfnt) at offset 0x17C0 7616 bytes