Malicious PDF — malware analysis report

Static analysis result for SHA-256 da7f42539f7605bd…

MALICIOUS

PDF

68.0 KB Authoring application: QPDF
MD5: 9fbc137d81ffa2c9aab20b31221c35d3 SHA-1: 5814c5d8842645683b54b9b56325eaa7b106c667 SHA-256: da7f42539f7605bdca2f2f719583ca469552a16d27508b5ec7902b7f4a62b45b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to other PDF files hosted on various domains. This technique is commonly used for SEO spam or to redirect users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, aligning with the PDF_SEO_LINK_FARM heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.emeraldsbeauty.com/uploads/1/3/0/7/130775201/4671319.pdf
    • http://mail.gfisystem.com/uploads/1/3/0/6/130604281/vepetul_fibuzezugo.pdf
    • http://i1drugs.trustquartet.com/uploads/1/3/0/6/130604327/turesolibinaseguz.pdf
    • http://mindandbodydallas.com/uploads/1/3/0/7/130776619/5254251.pdf
    • http://saloteflorist.com/uploads/1/3/0/6/130639530/daa470.pdf
    • http://mexiitems.com/uploads/1/3/0/4/130478819/4843770.pdf
    • http://evertonlovell.com/uploads/1/3/0/6/130620804/df842eb76237d.pdf
    • http://www.thecakeryathens.com/uploads/1/3/0/4/130483833/kerifoli-paxonu-siresij.pdf
    • http://secure.service-netflix.com/uploads/1/3/0/2/130288006/8953080.pdf
    • http://pyschicnetwork.live/uploads/1/3/0/4/130477228/xopajejirin.pdf
    • http://www.corvuspress.net/uploads/1/3/0/5/130539309/didadezotebezum_razibizudigav.pdf
    • http://moannasworkroominteriorsandstaging.com/uploads/1/3/0/4/130483811/tiparasota.pdf
    • http://readcloud10.com/uploads/1/3/0/8/130874347/6921759.pdf
    • http://robertcarroll-stamp.net/uploads/1/3/0/4/130488195/3c8aafcdb9.pdf
    • http://charityaweek.com/uploads/1/3/0/2/130270812/e62b6.pdf
    • http://connelyhitnews.com/uploads/1/3/0/7/130776877/3683707.pdf
    • http://miam-foundation.org/uploads/1/3/0/8/130813883/lopafa.pdf
    • http://hostmaster.handsonhexham.co.uk/uploads/1/3/0/8/130874029/5138207.pdf
    • http://www.oneformother.org/uploads/1/3/0/2/130287937/dakojewim_mofodupa_popiw.pdf
    • http://mx.enolaknezevic.com/uploads/1/3/0/9/130969235/8938894.pdf
    • http://npaevents.com/uploads/1/3/0/4/130476519/6519312.pdf
    • http://h3motorsportsmachinefabllc.com/uploads/1/3/0/5/130550855/124c5df0b.pdf
    • http://modern-bliss.net/uploads/1/3/0/3/130323485/9624739.pdf
    • http://xocobean.com/uploads/1/3/0/8/130813768/130813768.html#does+cosmic+ray+spallation+produce+boron

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000160f.bin
480f7be9cc10ce35ce64da78c4b904a74dc287009b951e3f9cf6fc0844ab0722
pdf-font-stream PDF embedded font (sfnt) at offset 0x160F 9040 bytes
font_01_sfnt_off0000b7e2.bin
5230b6665007f5c116ca1a3d16fe671494b14fd45c9f23f57ac500d7fe794436
pdf-font-stream PDF embedded font (sfnt) at offset 0xB7E2 16224 bytes
font_02_sfnt_off0000ccdf.bin
1110447959503c75238c0f1bcdf9de7fad567fc767730a4530dcb0d3a64541bd
pdf-font-stream PDF embedded font (sfnt) at offset 0xCCDF 2696 bytes