Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3c38ec70dc5eadb…

MALICIOUS

PDF

46.8 KB Authoring application: pstoedit
MD5: 0947ff48bc58d9630d68234038d57f8b SHA-1: de55f41e295dbae4727133b15f87a7afdf18656a SHA-256: e3c38ec70dc5eadb63187c410d5ed185945e9c99beed63967cb6276bf4d60535
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV also flagged this file as malicious, specifically as Pdf.Phishing.TtraffRobotInstall. The embedded URLs suggest a traffic generation or phishing scheme, aiming to direct users to various PDF documents hosted on different domains. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://researchsurf.org/uploads/1/3/0/4/130490915/vezigumopotox.pdf
    • http://rileysfullservice.com/uploads/1/3/0/5/130588590/1c1aa.pdf
    • https://nugojorazum.weebly.com/uploads/1/3/0/5/130551192/c3b7c6e9.pdf
    • http://12utct.com/uploads/1/3/0/4/130488734/mujufuroguzeg-sofedabet-lafex-samiziwevuladum.pdf
    • http://bandmcrushers.com/uploads/1/3/0/5/130545485/zapodeteguv_jirusebilono_tetuzof_xikufe.pdf
    • http://sgmurphy.com/uploads/1/3/0/3/130323641/1955711.pdf
    • http://animalandiagta.com/uploads/1/3/0/2/130272551/davefo.pdf
    • http://advance-it.net/uploads/1/3/0/7/130775258/130775258.html#hardest+math+problems+with+answers

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011d9.bin
5f8d148d094399d2a4f761cb04b125e59f35f151fb503700163b83f698c745df
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D9 8980 bytes
font_01_sfnt_off00007c13.bin
b43708cb5e62d241f3d01c6ae773d5c55721c2808c50ec44738901ee8420bf08
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C13 2796 bytes