Malicious PDF — malware analysis report

Static analysis result for SHA-256 cff8567c1fd40954…

MALICIOUS

PDF

38.5 KB Authoring application: Inkscape First seen: 2022-06-20
MD5: 5f11af74bb1729ce70e59e950af1c09b SHA-1: b1c33a03ec9d2743b71fd7ed0b554bccad507407 SHA-256: cff8567c1fd40954f1b076e93a13947e61c25ee2faea02ef2d58bbeadb5aa3ee
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://besodelsoltan.com/uploads/1/3/0/4/130436096/1616146.pdf In PDF document text
    • http://xetu.centrprava40.ru/uploads/2020/01/28/dce6bba9db2b55b.pdfIn PDF document text
    • http://artsequences.com/uploads/1/3/0/4/130436014/4650486.pdfIn PDF document text
    • http://closinggoals.com/uploads/1/3/0/6/130605435/mofudidunov.pdfIn PDF document text
    • http://stonefoxfeather.com/uploads/1/3/0/6/130605443/xudenelanibesaridi.pdfIn PDF document text
    • http://fur.mover-mser.icu/uploads/2020/01/28/f19ca91a471ca.pdfIn PDF document text
    • http://achintconsultinginc.com/uploads/1/3/0/5/130551607/rujeninoxekaji-wogeruz-mabijiva.pdfIn PDF document text
    • http://c5events.ca/uploads/1/3/0/4/130436121/tifenu.pdfIn PDF document text
    • http://tomakeandtobe.com/uploads/1/3/0/6/130604179/9a2d2b238d6124.pdfIn PDF document text
    • http://nqfd.com.au/uploads/1/3/0/5/130540725/gefomixaro-xusudoxonezurok.pdfIn PDF document text
    • http://lawrencepestpros.com/uploads/1/3/0/2/130288391/5e695ea12c3b43d.pdfIn PDF document text
    • http://openskydigitalmarketing.com/uploads/1/3/0/8/130814229/130814229.html#left+side+pleural+effusion+icd+10+codeIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000128a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x128A 7676 bytes
SHA-256: 29998503e5ad3e3d79c60e2bdff242fe81970d8b8cd59572a663baf92814cfe5