Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebccde406968e1d6…

MALICIOUS

PDF

35.0 KB Authoring application: ImageMagick
MD5: b64b08a5415e36e076d3d4f79d57021b SHA-1: 43296d5242069676d49fc681b92e18a27ace5a36 SHA-256: ebccde406968e1d64b05c265f6559a72267e51172436b35a8deccdadeff592bb
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of external links to other PDF files, a technique often used for SEO poisoning or to redirect users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs are the primary indicators of compromise, likely serving as lures for phishing or malware downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9922

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dieporzellanklinik.de/uploads/1/3/0/5/130539981/1286892.pdf
    • http://faberanot.skynetdonate.xyz/uploads/2020/01/28/7534019.pdf
    • http://paskiclub.ca/uploads/1/3/0/3/130313072/genupasibexunu.pdf
    • http://multistreams.com/uploads/1/3/0/3/130313198/130313198.html#gorillaz+feel+good+inc+sheet+music

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f9f.bin
1735fbbea16b7a779a4e68260e42a7c334abc9dbe4d7bd640144fff6d28a9624
pdf-font-stream PDF embedded font (sfnt) at offset 0xF9F 9448 bytes