Malicious PDF — malware analysis report

Static analysis result for SHA-256 e734c6e4dce709f0…

MALICIOUS

PDF

60.6 KB Authoring application: PDFBox
MD5: 4ab7364ab830c6160b7aee7d744d3c15 SHA-1: 18b6ca6317b5a1019ac6d4e13acb1069db327cfd SHA-256: e734c6e4dce709f05dd5a2f2c4d875e86050ae141ed146253b1968ee925036af
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The presence of a visual download button and the ClamAV detection of 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further support a phishing or malicious redirection scheme. The document body contains numerous URLs, suggesting the primary goal is to drive traffic to these external resources, likely for further exploitation or malware delivery.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ccanclegacyshootout.com/uploads/1/3/0/6/130620454/4153838.pdf
    • http://winningteamclub.com/uploads/1/3/0/5/130588973/magazoxesirez_gagejarizoze_limeruva_femefazuzabeb.pdf
    • http://www.inflatablesincwv.com/uploads/1/3/0/6/130621643/3787380.pdf
    • http://carolinawetlandservices.com/uploads/1/3/0/4/130483869/63252d6.pdf
    • http://www.knuckleswhiterock.com/uploads/1/3/0/8/130814169/jawuzam.pdf
    • http://simplescribe.net/uploads/1/3/0/6/130620234/sobesewepenawe-jagawus-bitupa.pdf
    • http://noraflum.org/uploads/1/3/0/6/130639856/b466b66e9e7a6b.pdf
    • http://www.atari2600homebrew.com/uploads/1/3/0/6/130639971/391827.pdf
    • http://portergames.net/uploads/1/3/0/5/130543050/666f31cf39cfa22.pdf
    • http://70-142-251-101.atemainc.com/uploads/1/3/0/3/130313557/52a39.pdf
    • http://www.avaatlanta.com/uploads/1/3/0/6/130605229/930138.pdf
    • http://sonrisasparadios.org/uploads/1/3/0/4/130436147/15ab7c.pdf
    • http://oldwillowcomplex.com/uploads/1/3/0/9/130969934/teroxu_wusinebof_legeso.pdf
    • http://kunalsen.org.uk/uploads/1/3/0/4/130435702/c31178fc89847.pdf
    • http://studioc229.com/uploads/1/3/0/4/130488743/bubamesovujetadezi.pdf
    • http://www.sunirobinarts.com/uploads/1/3/0/7/130775511/7e3f32b1b8b.pdf
    • http://nodeguard.octarinesec.com/uploads/1/3/0/8/130814863/ed83f.pdf
    • http://localnannys.com/uploads/1/3/0/5/130550696/63c7610bd.pdf
    • http://highclassshipping.net/uploads/1/3/0/4/130475984/wamobegava.pdf
    • http://golferman.com/uploads/1/3/0/5/130545581/setagukero_dogalovib_poregub.pdf
    • http://filoulefoufou.com/uploads/1/3/0/6/130620314/3623594.pdf
    • http://orcharddistrictneighborhood.com/uploads/1/3/0/6/130621194/fuwamuwiwa.pdf
    • http://pofcalls-enable.com/uploads/1/3/0/6/130639926/d73182.pdf
    • http://haiwangxingxianshangyuledaili.br3h.com/uploads/1/3/0/2/130288893/130288893.html#the+complete+sherlock+holmes+volume+1+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001207.bin
dc9664aed44d5ec7a55140e831aaf398f46f9de7eefed54694154dd28148b430
pdf-font-stream PDF embedded font (sfnt) at offset 0x1207 9920 bytes
font_01_sfnt_off000095c7.bin
9060487a9c91bd431a3bcd73191f93313a97d09d2f6cba2c488d422564fed6b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x95C7 16564 bytes