Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8520cb58eee3895…

MALICIOUS

PDF

38.4 KB Authoring application: pstoedit
MD5: 68e9e68bb4ba7e3e231b86f38671176e SHA-1: a287c3a4b285e98ce7d49bd24b6f125c61456c47 SHA-256: e8520cb58eee38955485b509c555d6d796ef3734a4427a21de91b07b36b22b10
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, which is indicative of a phishing or malicious redirection attempt. The document body, though partially corrupted, mentions 'ACT test taking tips for english', suggesting a lure to disguise the malicious intent. The embedded URLs are likely used to host further malicious content or redirect to phishing pages.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://youthbuildillinois.org/uploads/1/3/0/3/130323337/3229917.pdf
    • http://vintagefairedecor.com/uploads/1/3/0/5/130540746/1225738.pdf
    • http://dekelamob.stroimontag123.ru/uploads/2020/01/28/luxat-wutazovus-zaroxatoba.pdf
    • http://neokundalini.org/uploads/1/3/0/8/130814531/130814531.html#act+test+taking+tips+for+english

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000100e.bin
cc1cfe5bb8c68617b13f4475505676bd4660c686d5d03ffcd29ab2af001df054
pdf-font-stream PDF embedded font (sfnt) at offset 0x100E 8652 bytes