Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea090a6ab10a0c57…

MALICIOUS

PDF

35.8 KB Authoring application: Scribus
MD5: 84d147d1fe37a3b222176de15491052f SHA-1: d8eea7e5f5621f4d9f0ff16169a0a5f51a4eb2d7 SHA-256: ea090a6ab10a0c578e86a71463c62acd80b87ea4392ac9120fa33d17b18e5566
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.003 Phishing: Spearphishing Attachment T1204.001 User Execution: Malicious Link

The sample is a PDF containing a large number of external links to other PDFs, characteristic of an SEO link farm used to manipulate search engine rankings and drive traffic to malicious sites. While the document body contains nonsensical text about whitetail deer, the high volume of URLs and the PDF_SEO_LINK_FARM heuristic firing confirm the intent. No scripts were extracted from this sample.

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://hostmaster.esteemengineers.com/uploads/1/3/0/5/130550708/wunofolo-zujoxeveto-xotobituxosaxis-wedisevumokere.pdf
    • http://happystraystories.com/uploads/1/3/0/6/130639592/4484249.pdf
    • http://alabamaassure.com/uploads/1/3/0/2/130271061/rakawabola.pdf
    • http://nuno-dias.com/uploads/1/3/0/3/130323707/8196444.pdf
    • http://sallycasey.com/uploads/1/3/0/8/130814900/8d672604e770ed4.pdf
    • http://airbornelidarservices.com/uploads/1/3/0/5/130541743/fe2eb57.pdf
    • http://natashasfantastic5dollarbling.com/uploads/1/3/0/6/130620233/jirujaz.pdf
    • http://marijuanacultivationconsultant.com/uploads/1/3/0/2/130289577/5252652.pdf
    • http://brismakingchanges.com/uploads/1/3/0/3/130379307/nirumugigux.pdf
    • http://113366.co/uploads/1/3/0/5/130546923/xututalufag-jotuberuvigatog-lafaboj.pdf
    • http://menfixed.com/uploads/1/3/0/6/130604692/4fff4.pdf
    • http://aikosilkart.net/uploads/1/3/0/3/130313053/gumoz.pdf
    • http://scf-token-info.com/uploads/1/3/0/5/130551477/vupilan.pdf
    • http://sarahpoulgrain.com/uploads/1/3/0/8/130813111/f8cbec45cdb7e.pdf
    • http://jamesmcleodvo.com/uploads/1/3/0/2/130288909/pinobuxut-gevedinafij-kokefopin.pdf
    • http://cesartechnologiesltd.com/uploads/1/3/0/2/130287953/gapumenokabobokix.pdf
    • http://bsa-sccc-pack301.com/uploads/1/3/0/3/130323339/130323339.html#boone+and+crockett+whitetail+north+dakota

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f63.bin
4e81edb7f36ccdeab5d39cff8c117a25fc14c20a966e4ab231cd795d160a2513
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F63 7992 bytes