Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2fd3ca622b7ffde…

MALICIOUS

PDF

41.3 KB Authoring application: Poppler-utils
MD5: 8d860ae5203c028334215ee27066aeca SHA-1: 91106da2c5764134774291da3e30793cecb2b18a SHA-256: e2fd3ca622b7ffde4e8e06d9702c5ca06994894e66f372e29f733849f782012b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, a technique often used for SEO poisoning or to direct users to malicious websites. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic redirection intent. No scripts were extracted from this sample, and the document body content is heavily corrupted, making it difficult to ascertain a more specific attack pattern beyond link distribution.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thelandbetween.org/uploads/1/3/0/4/130483397/675c4777498e51.pdf
    • http://riseandshinekombucha.com/uploads/1/3/0/6/130620197/78fc273e24b.pdf
    • http://mynativegardenoasis.net/uploads/1/3/0/7/130740371/rixedatokepo.pdf
    • http://tradeshowsinphoenix.com/uploads/1/3/0/7/130775402/zosofilinizu.pdf
    • http://uniquetextilesexperts.com/uploads/1/3/0/8/130813416/benidoxofitixok.pdf
    • http://www.moment2meditate.org/uploads/1/3/0/4/130476242/5e720ea270.pdf
    • http://opensourcedw.com/uploads/1/3/0/3/130323581/d50bd4454.pdf
    • http://nworparenting.com/uploads/1/3/0/5/130588856/b88bbc1eb7d638a.pdf
    • http://debbrockmanstudios.com/uploads/1/3/0/3/130323415/kujenogele.pdf
    • http://ridgeroadtiburonlot.com/uploads/1/3/0/5/130589345/7665955.pdf
    • http://hostmaster.themobilityfactory.eu/uploads/1/3/0/8/130874307/bukon.pdf
    • http://www.mrsranard.com/uploads/1/3/0/5/130538902/130538902.html#flow+sensor+arduino+diagram

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000047d1.bin
ce5b8bb833eda008c2f3a11d63a11da1d7fd8a81085eb793655936a9c71d345b
pdf-font-stream PDF embedded font (sfnt) at offset 0x47D1 9108 bytes