Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6ef068aecad5fb5…

MALICIOUS

PDF

43.5 KB Authoring application: ImageMagick
MD5: d55a23fb8e21c58adfacd8ca063bd7dd SHA-1: 1afae408540a02f7053711b12392b0bf33923aa6 SHA-256: d6ef068aecad5fb58dee096d15581edc9814670651bc41567d762278bf800f26
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO spam or to redirect users to malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs are the primary indicators of compromise, suggesting a redirection or content-loading attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://4therestofus.com/uploads/1/3/0/4/130435695/d6f0f9511bf1.pdf
    • http://sarinabenn.com/uploads/1/3/0/7/130739928/3989226.pdf
    • http://manwithgunband.com/uploads/1/3/0/7/130776399/jitulamapovigum-papalapegowut-wonuxod.pdf
    • http://copperheadfarm.com/uploads/1/3/0/2/130291531/5216539.pdf
    • http://bishophomeservices.com/uploads/1/3/0/7/130775606/nonutisuriwapisodip.pdf
    • http://spacecookies.us/uploads/1/3/0/5/130540585/palasu.pdf
    • http://hostmaster.lion-fabrications.com/uploads/1/3/0/3/130379192/runapewizenaxogu.pdf
    • http://jymstringer.com/uploads/1/3/0/7/130739852/68fa1e21b0cc9.pdf
    • http://wisconsinlimousin.org/uploads/1/3/0/3/130323535/tozonivenov_momedureg.pdf
    • http://thereirockstar.com/uploads/1/3/0/4/130435670/bapazovokevedexumur.pdf
    • http://gitanno.com/uploads/1/3/0/6/130604379/bokovipugutiz_pejifid.pdf
    • http://nilakim.com/uploads/1/3/0/7/130740316/zimitu.pdf
    • http://mytrophyprofile.net/uploads/1/3/0/3/130324236/sobulos_kubepisigeju.pdf
    • http://mofflongboards.com/uploads/1/3/0/8/130814575/0713c5e162a4.pdf
    • http://spreadscience.org/uploads/1/3/0/7/130739928/6634458.pdf
    • http://nylarose.co/uploads/1/3/0/4/130476766/2038439.pdf
    • http://lifeschooleugene.org/uploads/1/3/0/7/130775567/6e6b7d09e4.pdf
    • http://savinginstead.com/uploads/1/3/0/6/130620587/29ba313c30f3915.pdf
    • http://sweetwatermanors.com/uploads/1/3/0/5/130542991/3399322.pdf
    • http://ga65q.slpny.com/uploads/1/3/0/6/130621988/130621988.html#pseudocode+bubble+sort+java

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003a4c.bin
d2e7eed78c6daee388634f2a284a23ba3042f90c059d1d6520916ad0c4b740bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x3A4C 2776 bytes
font_01_sfnt_off0000475e.bin
c81538f33722542a8f8ae3e56aa69ec7e69289bffbc3a4c11bd99e0714b8ea83
pdf-font-stream PDF embedded font (sfnt) at offset 0x475E 9860 bytes