Malicious PDF — malware analysis report

Static analysis result for SHA-256 eeaca070732419d7…

MALICIOUS

PDF

51.3 KB Authoring application: PDF Studio
MD5: 4418afc59aad6b856ceebd04590dec8a SHA-1: d996188f21e968238cd36d151462ddb8385b5537 SHA-256: eeaca070732419d7c6ddf6f944dd63823043ac3b8f18ce5c18f5a62f6c6d0e52
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection as Pdf.Phishing.TtraffRobotInstall-7605656-0 further supports its malicious nature. The document body, though heavily obfuscated, contains URLs that are part of this link farm. The primary attack pattern appears to be SEO manipulation or distributing malicious content via a link farm.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bc-observations.com/uploads/1/3/0/2/130274028/510854.pdf
    • http://kuto.fmmoduliator.store/uploads/2020/01/27/1e92149fd6e5c.pdf
    • https://tijafusefekaj.weebly.com/uploads/1/3/0/3/130313188/ec1b2e0a002a386.pdf
    • http://nzshv.ru/uploads/2020/01/29/zejekesesilizafut.pdf
    • http://9thwonderco.com/uploads/1/3/0/4/130436362/vulutejesupaza.pdf
    • http://s-w-p.org/uploads/1/3/0/3/130323210/b36df6d1357735b.pdf
    • http://lettucefinancial.com/uploads/1/3/0/6/130620472/8950624.pdf
    • http://rosestroh.com/uploads/1/3/0/6/130603682/3324387.pdf
    • http://datene.elizabeth-health.info/uploads/2020/01/28/begited-tipomafexogir-vuvones-kifedifedeb.pdf
    • http://coffeetimenews.ca/uploads/1/3/0/5/130590702/b7604a22fdb71af.pdf
    • http://evidentone.com/uploads/1/3/0/2/130291640/35b48622c500.pdf
    • http://jixejesa.serovatextile.ru/uploads/2020/01/27/771bae6.pdf
    • http://jow.najiyagalimova.com/uploads/2020/01/27/8022239.pdf
    • https://wilukitivuj.weebly.com/uploads/1/3/0/5/130541600/6614013.pdf
    • http://fofolirej.my-smile.top/uploads/2020/01/27/sosuzolunulej-gawotizoraxes.pdf
    • http://kateyanne.com/uploads/1/3/0/6/130639856/a79f32014a34.pdf
    • http://runiz.nikulin-ildar.ru/uploads/2020/01/27/df8b8dca73d56a.pdf
    • http://copybyvan.com/uploads/1/3/0/5/130551115/be8d1207ca6b.pdf
    • http://kimberlifreilinger.com/uploads/1/3/0/3/130323693/dd291.pdf
    • https://kigituwininerev.weebly.com/uploads/1/3/0/3/130379381/62869f.pdf
    • https://zuvobemidefofod.weebly.com/uploads/1/3/0/2/130272352/risop_biwoliveb.pdf
    • http://kavkaz-car.ru/uploads/2020/01/27/55e941a0a.pdf
    • http://awcfund.weebly.com/uploads/1/3/0/5/130589159/zabuvefagedep-miwenetewi-bujokuzapibef.pdf
    • http://parfumsoo.ru/uploads/2020/01/28/womuzagekojomu-viloxese-dutoxaron-tusekilu.pdf
    • http://oakclass.com/uploads/1/3/0/2/130270989/130270989.html#splayer+1.+1+apk

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000174e.bin
ddea4ee4ef1dcb7997b66d875fdb30e9eefcf3dcdfcbd32c2add290bef74dd51
pdf-font-stream PDF embedded font (sfnt) at offset 0x174E 8100 bytes
font_01_sfnt_off000067bd.bin
fd5f80c928a41697f05a8a9d996a29eb187ea710f31dd7faa306f8bad5585866
pdf-font-stream PDF embedded font (sfnt) at offset 0x67BD 11444 bytes
font_02_sfnt_off00008092.bin
61f39a40fab5b3b9b086e472833cb72536825936d28bb1fbe8a9e4663b14a83c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8092 6648 bytes