Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8f38a175370fc7a…

MALICIOUS

PDF

93.2 KB Authoring application: ImageMagick
MD5: c7ed81285bce593861bd7d00a0669974 SHA-1: a8de2fe23e282688214e77791ca96d8a5f2edfa2 SHA-256: e8f38a175370fc7a88902d2918d9fbfb4cbc8b8ec1220ad367a78ec60b47a282
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was flagged by multiple heuristics as malicious, including a critical PDF_SEO_LINK_FARM rule indicating a large number of external links. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports its malicious nature. The primary attack pattern involves redirecting users to numerous external PDF files hosted on various domains, likely for SEO manipulation or to serve further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocalaprestigecleaning.com/uploads/1/3/0/5/130590464/gabutavofusug.pdf
    • http://ahighrpowr.com/uploads/1/3/0/4/130476298/fejos.pdf
    • http://ezyfix2u.com/uploads/1/3/0/4/130436074/rigovaxaroraw.pdf
    • http://newsolutionsit.com/uploads/1/3/0/7/130775002/2639893.pdf
    • http://www.rsmcmillanpublishing.com/uploads/1/3/0/9/130969012/1071056.pdf
    • http://www.qwyzer.org/uploads/1/3/0/5/130547515/138528.pdf
    • http://ktrpo.com/uploads/1/3/0/4/130476078/4820731.pdf
    • http://varietysmile.com/uploads/1/3/0/6/130639404/1294256.pdf
    • http://www.courtstrengthllc.com/uploads/1/3/0/5/130542964/4b5df07.pdf
    • http://kccouplesworkshop.com/uploads/1/3/0/7/130775109/fukiri.pdf
    • http://cothamsinthecity.com/uploads/1/3/0/7/130738798/2223175.pdf
    • http://innerkeyhypnotherapy.com/uploads/1/3/0/2/130288379/cab71b1cce.pdf
    • http://thanksvember.com/uploads/1/3/0/8/130814630/xoxapesobefax.pdf
    • http://getstyledbylulu.com/uploads/1/3/0/5/130543320/4385505.pdf
    • http://www.doveshanksbitters.com/uploads/1/3/0/7/130740187/182597c555fbe.pdf
    • http://redondobeachheating.net/uploads/1/3/0/4/130436271/dibagasaj-sesukirudirurig.pdf
    • http://craigkiselbach.com/uploads/1/3/0/2/130291492/9225552.pdf
    • http://operationalysha.com/uploads/1/3/0/4/130435499/tovugirupitopor-xarufetojisir-xumarevexi.pdf
    • http://travel-merit.com/uploads/1/3/0/7/130740087/jexup_wezosuvonipix.pdf
    • http://audiopron.com/uploads/1/3/0/4/130476024/8371037.pdf
    • http://workplaceptsdrecovery.com/uploads/1/3/0/8/130813663/5868909.pdf
    • http://3plids.com/uploads/1/3/0/6/130639790/ad2b6.pdf
    • http://marketingvampire.com/uploads/1/3/0/3/130323212/kozulogipon.pdf
    • http://amarinlagoonhotel.devsite-1.com/uploads/1/3/0/4/130476322/130476322.html#sjogren%27s+syndrome+prognosis
    • http://www.rsmcm

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004fb0.bin
3b76adee2ebc42593fbf18789b9121c3f07b7c3e8fb5d4085a63f061689e91bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x4FB0 10916 bytes
font_01_sfnt_off00011a37.bin
f5f3c87b537fe5191b55908a1c6de3d1f2d5874545fb1bf28ec645563481a303
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A37 3284 bytes
font_02_sfnt_off0001255f.bin
3bf217192b5503dfe087ed1ce3529886756d9d7764f051ab8dbbff57ebd60bb5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1255F 16964 bytes