Malicious PDF — malware analysis report

Static analysis result for SHA-256 e667390aaca51ae7…

MALICIOUS

PDF

42.5 KB Authoring application: LibreOffice Draw
MD5: ce24752b082d86537194038b99c57a40 SHA-1: f4650f7b129fcc2de71438eb135fcb3d8eacadc6 SHA-256: e667390aaca51ae745cb4b0e030f9edbb05ffd9dcf663d9bc35aab3339586af3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs pointing to external PDF files, a technique commonly used for SEO spam or to redirect users to malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically related to phishing or unwanted content distribution. No scripts were extracted, but the sheer volume of linked domains suggests a coordinated effort to distribute harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://richbassviolin.com/uploads/1/3/0/3/130313188/mudamopuzega.pdf
    • http://green-ct.com/uploads/1/3/0/5/130551089/taxitomiv.pdf
    • http://wibier.nl/uploads/1/3/0/4/130436513/rojodipe.pdf
    • http://easternmedia.ca/uploads/1/3/0/6/130603909/juzif.pdf
    • http://prolinelifepharmaceutical.com/uploads/1/3/0/5/130590663/64b8ea08e8b0.pdf
    • https://sugewisu.weebly.com/uploads/1/3/0/4/130483271/5725434.pdf
    • https://dolegazori.weebly.com/uploads/1/3/0/3/130313746/timuzamuzoritijus.pdf
    • http://wenebe.superstudy.ru/uploads/2020/01/28/vokor.pdf
    • http://antivirussguardservice.xyz/uploads/2020/01/27/96469173bd8.pdf
    • http://1001edrutherford.com/uploads/1/3/0/5/130544110/wuxatibibig.pdf
    • http://africancatclub.com/uploads/1/3/0/4/130483737/8249776.pdf
    • https://fozepitiv.weebly.com/uploads/1/3/0/6/130604036/xabolo_gutizodusufosiw_sovomakogusiker_wovomuzebug.pdf
    • http://fewigibine.swiftfoxit.tech/uploads/2020/01/27/2368358.pdf
    • http://lobijeseti.suot.pro/uploads/2020/01/27/fumusapeli.pdf
    • http://wanderlust-girl.com/uploads/1/3/0/5/130588343/5ccd9e45e975.pdf
    • https://tazelojovizazad.weebly.com/uploads/1/3/0/4/130483741/mofevurakupewaju.pdf
    • https://zolelajemexif.weebly.com/uploads/1/3/0/2/130270833/zizen-vuvezovim.pdf
    • http://rachelheater.com/uploads/1/3/0/2/130288486/7421535.pdf
    • http://duzutot.osada.fun/uploads/2020/01/29/jafugobasene.pdf
    • http://urfacefix.com/uploads/1/3/0/5/130588872/130588872.html#the+red+tent+torrent

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000015b5.bin
1f5e18694d692083ed08645efc2f263956dfc7200520cfdb5e90076e0580b525
pdf-font-stream PDF embedded font (sfnt) at offset 0x15B5 9172 bytes
font_01_sfnt_off00005cd9.bin
75a001a6a8f15397936a8e26ccaca996903a3504da7109047014097407cd22d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CD9 16640 bytes