Malicious PDF — malware analysis report

Static analysis result for SHA-256 e29c4a2e0bd553ec…

MALICIOUS

PDF

28.7 KB Authoring application: Soda PDF
MD5: 70ee048c61961ad367efd0640eb1f4e5 SHA-1: 27a7b6ed62fe83a00e558fe31dd16775a4635728 SHA-256: e29c4a2e0bd553ec651633fb675e7dca4a980a049d6ebbb59b3dec5795be05f3
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded URLs, identified as a link farm. This is strongly indicative of a phishing or SEO poisoning attack, aiming to redirect users to malicious websites. The ClamAV detection further supports its malicious nature. No scripts were extracted, and the document body was heavily corrupted, limiting further analysis of specific lures.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://acerecoverygroup.com/uploads/1/3/0/2/130271102/dafowalam-rojiza-nigadiwubapak-degojumasexebub.pdf
    • http://www.safeconntech.com/uploads/1/3/0/6/130621185/fubojijabemo.pdf
    • http://pimpampaint.com/uploads/1/3/0/3/130379894/zasige.pdf
    • http://iloveus.co/uploads/1/3/0/5/130588360/bodutajisosalijade.pdf
    • http://www.sweetcsvino.com/uploads/1/3/0/8/130874601/vumimeres.pdf
    • http://pof-addcallsettings.com/uploads/1/3/0/3/130313021/830845.pdf
    • http://www.2peasinthepod.ca/uploads/1/3/0/4/130483364/6160449.pdf
    • http://myaffiliatepages.org/uploads/1/3/0/7/130739864/ruwozox.pdf
    • http://breimhurst.com/uploads/1/3/0/5/130552034/jumudo.pdf
    • http://rossloto.site/uploads/1/3/0/4/130483123/bomepulizevimofex.pdf
    • http://taylororchards.net/uploads/1/3/0/6/130620340/joguvezitofomowax.pdf
    • http://www.byrafidah.com/uploads/1/3/0/5/130550936/6481213.pdf
    • http://theharrishawkinshometeam.com/uploads/1/3/0/5/130550774/turomugafenibasorek.pdf
    • http://digitalfreebies.net/uploads/1/3/0/7/130739793/tololelelabon.pdf
    • http://cpanel.trvea.org/uploads/1/3/0/5/130551188/ae1c6b85c5.pdf
    • http://oceanheartherapy.com/uploads/1/3/0/2/130288709/9927458.pdf
    • http://christinafriedle.org/uploads/1/3/0/9/130969424/130969424.html#the+crucible+act+2+study+questions+and+answers+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000018b5.bin
c69f85e948c28c1ce9d8cf0a8bbf57d25fcfeff109dfbe78159fcb44af39ead4
pdf-font-stream PDF embedded font (sfnt) at offset 0x18B5 6240 bytes