Malicious PDF — malware analysis report

Static analysis result for SHA-256 d03aa5887515e856…

MALICIOUS

PDF

37.3 KB Authoring application: Pdftk
MD5: 33f01a430f683d695a9819cea14a9ce3 SHA-1: 936dfc23267146c2edaef1dc47ea72de0c4ccda0 SHA-256: d03aa5887515e856df38267ca713f40a716302319fed27b16a735ab7ebb70968
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the 'PDF_SEO_LINK_FARM' heuristic, which strongly suggests a link farm or redirection scheme. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output further support a malicious classification. The embedded URLs are likely used to direct users to malicious websites or to manipulate search engine rankings.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://4lifehealthwealth.com/uploads/1/3/0/4/130478307/f3431f.pdf
    • http://mycityrebate.com/uploads/1/3/0/2/130272930/483732.pdf
    • http://www.lot4lloyds.com.au/uploads/1/3/0/6/130604594/masadusejoda-xaratumod-famitudowepevep-xexujetidebitil.pdf
    • http://alanmaps.com/uploads/1/3/0/7/130775587/992a9f9e12cad2.pdf
    • http://pairofjacks.net/uploads/1/3/0/2/130274349/6724786.pdf
    • http://joemathewson.net/uploads/1/3/0/8/130814716/xexoka-piwosajuzizegu-lanumepi-kuxuwakujew.pdf
    • http://plr.group/uploads/1/3/0/7/130740206/06af1bdf.pdf
    • http://www.art8light.com/uploads/1/3/0/7/130775629/af9d820b4c616.pdf
    • http://gebreabzere.com/uploads/1/3/0/2/130287269/5461730.pdf
    • http://alfredveretto.com/uploads/1/3/0/4/130488362/zoxumarezava.pdf
    • http://sjsbeacon.com/uploads/1/3/0/5/130588489/bee8c41.pdf
    • http://fiscalnoteevents.com/uploads/1/3/0/8/130813115/vomakalagukuvejose.pdf
    • http://introtovideo.com/uploads/1/3/0/5/130550792/novoxipegiwiraxojet.pdf
    • http://ps163taskforce.org/uploads/1/3/0/5/130539492/eca4a3.pdf
    • http://daffodil-11.org/uploads/1/3/0/2/130291786/pefekabaripaz.pdf
    • http://millerpost.net/uploads/1/3/0/6/130620882/zutod.pdf
    • http://valleyofhemp.com/uploads/1/3/0/7/130775306/4d7bf6dd75.pdf
    • http://www.lifesimpressions.us/uploads/1/3/0/6/130604307/2009204.pdf
    • http://moorelaughing.com/uploads/1/3/0/7/130739015/2d225.pdf
    • http://nextdeavor.net/uploads/1/3/0/8/130814758/buxexa-wurakoteru-vudorososodid-xofowumog.pdf
    • http://chamoisinfo.com/uploads/1/3/0/5/130542983/diwuk.pdf
    • http://littlecuriositycorner.com/uploads/1/3/0/6/130603704/sotiwopesemoko.pdf
    • http://mx.thebiggroove.com/uploads/1/3/0/9/130969950/705616.pdf
    • http://westboro-apts.ca/uploads/1/3/0/7/130776399/0966223bb235.pdf
    • http://mx0.monquartier.org/uploads/1/3/0/5/130539235/6ecb48.pdf
    • http://host246.carmichaelnl.com/uploads/1/3/0/3/130324351/130324351.html#the+role+of+mass+media+as+agent+of+socialization+on+nigeria+youth
    • http://pairofjac

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f6a.bin
45154c95455918ca4f5195c2bc3065662b6dba9e77feff13595f6c29bdb90319
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F6A 7272 bytes