Malicious PDF — malware analysis report

Static analysis result for SHA-256 d57bde1adb9f1f81…

MALICIOUS

PDF

39.8 KB Authoring application: PDFedit
MD5: f9a12ce9bfabc3caf176b783d01c0ff5 SHA-1: c5fa741f48ac3eba3b254a6f5a88e20884e5ecd1 SHA-256: d57bde1adb9f1f81435cf4c914305266573055dc3cbdac01fa62b9e520ba6c71
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The PDF was flagged by multiple heuristics, including a critical finding for a large number of external links, suggesting a link farm or redirection scheme. ClamAV also identified it as phishing malware. The embedded URLs point to various domains, all likely part of the same malicious infrastructure. The document body contains garbled text and what appears to be a reference to a PDF guide, but the primary malicious activity is the extensive link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://replaceyourwoman.com/uploads/1/3/0/5/130550690/sotezubat_tutigokiwikux_javalenepe.pdf
    • http://hostmaster.zionchristianretreat.org/uploads/1/3/0/6/130639484/baxolirametaw.pdf
    • http://back2hemp.com/uploads/1/3/0/5/130588393/moral.pdf
    • http://assistensepay.live/uploads/1/3/0/8/130814642/d84bceba6881.pdf
    • http://edc1.stacks411.com/uploads/1/3/0/3/130313196/90a9980.pdf
    • http://noahcompportfolio.com/uploads/1/3/0/5/130551882/942794fd61c.pdf
    • http://coateschicken.com/uploads/1/3/0/5/130545932/dofalaj.pdf
    • http://charlesdickensjewelry.com/uploads/1/3/0/5/130588261/290f8a4ff3ff7.pdf
    • http://dataforgood.design/uploads/1/3/0/3/130324419/makepubuni_wesabagukuk.pdf
    • http://northeastwildernesscompany.com/uploads/1/3/0/7/130775949/4972266.pdf
    • http://www.conceptsingreenaustralia.com/uploads/1/3/0/5/130550681/85d7e2b0f2db.pdf
    • http://neogastro.com.gt/uploads/1/3/0/3/130379231/sobitep.pdf
    • http://bodywellnesskelowna.com/uploads/1/3/0/6/130639055/winebajasori-novivejovake.pdf
    • http://quantumlevelsoulhealing.com/uploads/1/3/0/2/130287953/wevatoxoxelimon_wefowalagidep_rolarufoko_pejoxitosevu.pdf
    • http://morganadvisory.net/uploads/1/3/0/5/130588145/3474329.pdf
    • http://www.seleneskincare.com/uploads/1/3/0/5/130539188/baremabuguz.pdf
    • http://mytexasbankruptcylawyers.com/uploads/1/3/0/6/130604579/zogopifaxemanazukivo.pdf
    • http://casinotify.com/uploads/1/3/0/3/130323959/01085e.pdf
    • http://tcsis.co.uk/uploads/1/3/0/6/130640231/pezafuje.pdf
    • http://zoeapos.com/uploads/1/3/0/4/130476370/148e6.pdf
    • http://hostmaster.batl.org.uk/uploads/1/3/0/6/130621626/pudabilokufu_mizegagiremub.pdf
    • http://www.militarypromos.net/uploads/1/3/0/3/130379332/tonibugeju-judem.pdf
    • http://rideandtrain.com/uploads/1/3/0/6/130639939/jaraladapi.pdf
    • http://ktofineart.com/uploads/1/3/0/7/130776730/xowoveledax.pdf
    • http://cheerloveproject.com/uploads/1/3/0/6/130620185/a171050d.pdf
    • http://74-123-76-23.mgwnet.com/uploads/1/3/0/2/130287401/130287401.html#pathways+3+reading+writing+and+critical+thinking+teacher%27s+guide+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000208c.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x208C 16036 bytes
font_01_sfnt_off00003759.bin
735cee5d9ae378506db9b04c7206a8f86eeb9fce5dd4666b8e1b5c191b590848
pdf-font-stream PDF embedded font (sfnt) at offset 0x3759 7508 bytes