Malicious PDF — malware analysis report

Static analysis result for SHA-256 db323f56d510538b…

MALICIOUS

PDF

35.8 KB Authoring application: GIMP
MD5: f71149e0862db8f1b22df3b2c1842426 SHA-1: 19960a08f9217c6d37cc8f3f232fa9fae7218401 SHA-256: db323f56d510538b8dc14edeaacfb539dbb4808970efb69660289b574cbbf585
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, identified as a link farm, directing users to various PDF files hosted on different domains. This technique is commonly used for SEO poisoning or to distribute malware. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://newdreamrenovations.com/uploads/1/3/0/4/130489358/buniworaxaz.pdf
    • http://africanliongroup.com/uploads/1/3/0/6/130621838/4092537.pdf
    • http://assortedartistries.net/uploads/1/3/0/7/130775528/0219d4203092f2a.pdf
    • http://ndbc-shanghai.com/uploads/1/3/0/5/130551729/wurijijo_mawuminajimenid_joxadufol_mojud.pdf
    • http://trophybearer.org/uploads/1/3/0/6/130604370/xevevis.pdf
    • http://starvedrockcountryresort.com/uploads/1/3/0/8/130814284/278848.pdf
    • http://visualizeus.net/uploads/1/3/0/5/130547024/9588972.pdf
    • http://www.managerlog.us/uploads/1/3/0/2/130289779/9742353.pdf
    • http://creditfromhome.net/uploads/1/3/0/7/130739558/e3b902464e.pdf
    • http://mrsottocounselingcorner.com/uploads/1/3/0/4/130435726/8259fff.pdf
    • http://fitfoodsexpress.com/uploads/1/3/0/5/130588318/9211911.pdf
    • http://advertisingarchives.net/uploads/1/3/0/6/130639571/benemanura.pdf
    • http://pranzotruck.com/uploads/1/3/0/6/130639653/130639653.html#adobe+pdf+reader+download+free+for+windows+7
    • http://assorted

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003394.bin
286aa2f25aa64eb3f2767fed7016d22e1cd0d946f38210c2cd46696e80dee725
pdf-font-stream PDF embedded font (sfnt) at offset 0x3394 8044 bytes