Malicious PDF — malware analysis report

Static analysis result for SHA-256 d569ac7d49f151a0…

MALICIOUS

PDF

38.4 KB Authoring application: Smallpdf Desktop
MD5: 5bd78af8d26ee45e749f68f5fa153aaf SHA-1: a27d29229c08c7ac38de04e67216c5b791936277 SHA-256: d569ac7d49f151a035c372b6ffb58a8b6075481f8b05e48a2c62191458cbd019
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The document body text attempts to lure users by offering 'profit and loss statement sample documents'. The ClamAV detection further confirms its malicious nature, classifying it as Pdf.Phishing.TtraffRobotInstall. The embedded URLs are likely used to redirect users to malicious content or further stages of an attack.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://advbioco.com/uploads/1/3/0/2/130287842/9eaa5acdc.pdf
    • http://conniezator.com/uploads/1/3/0/7/130775921/rexos_pibab.pdf
    • http://alvagaleria.com/uploads/1/3/0/3/130323466/4146915.pdf
    • http://7soundenergy.com/uploads/1/3/0/4/130475992/e3ad35.pdf
    • http://afaparents.org/uploads/1/3/0/7/130775558/130775558.html#profit+and+loss+statement+sample+document

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001001.bin
5b2db3570d9bf26c79d29e643346554460302b242c8cfa94f74417a74b3d10c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1001 8400 bytes