Malicious PDF — malware analysis report

Static analysis result for SHA-256 f160952ef6e7de09…

MALICIOUS

PDF

39.4 KB Authoring application: Smallpdf Desktop
MD5: 2d8a5a8d670327c5870ac015ba4b4bbe SHA-1: 06ee02b72dfd300df75e93859bb717f79ca52b8f SHA-256: f160952ef6e7de09b20ce80d0517144e2cd6890a37feb2b67da1a2d361474cb7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious phishing content. The primary attack pattern involves a link farm of 30 external PDF URLs, suggesting an attempt to manipulate search engine results or distribute further malicious content. The document body contains text related to mosquito classification, which appears to be a lure to disguise the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bus.dmdmassage.com/uploads/2020/01/27/basividu.pdf
    • http://lite-zaim.ru/uploads/2020/01/27/6bd0714fe222f.pdf
    • http://kitel.talequale.pw/uploads/2020/01/27/1645397.pdf
    • http://tuz.irbispartner.ru/uploads/2020/01/27/keropedogavuzer.pdf
    • http://ndhaquascapes.com/uploads/1/3/0/2/130288427/xojebutotof_wajadatu.pdf
    • http://repuw.smileshop10.ru/uploads/2020/01/29/6a8975dd8056e48.pdf
    • https://buvajufa.weebly.com/uploads/1/3/0/3/130379155/a5838e003580.pdf
    • http://carlsbadmobiledetail.com/uploads/1/3/0/6/130621755/10ec831e91b10.pdf
    • http://gezoz.fabrika-perchatok.com/uploads/2020/01/28/muxeluvalaw_gedokelefi_lakelu_xexozo.pdf
    • https://jivawodumifus.weebly.com/uploads/1/3/0/5/130550693/5548252.pdf
    • http://sicpsycles.com/uploads/1/3/0/3/130379081/8346118.pdf
    • http://bipa.massrage.ru/uploads/2020/01/28/9295081.pdf
    • http://lead2rose.com/uploads/2020/01/28/gonikoz_zivodugor_kagefamebafales.pdf
    • http://lindseyvlasman.com/uploads/1/3/0/4/130483322/7991eee25416f6.pdf
    • http://xenov.penostroy.com/uploads/2020/01/28/fazesurida-sodazigikakukag.pdf
    • http://rightdevelopmentfoundation.com/uploads/1/3/0/2/130271068/130271068.html#classification+of+anopheles+mosquito+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000141f.bin
9f53d48593ab67bf75c6053245d87ba3078072437e3a36ef712cfbeafe528738
pdf-font-stream PDF embedded font (sfnt) at offset 0x141F 8072 bytes