Malicious PDF — malware analysis report

Static analysis result for SHA-256 f57cac7736241215…

MALICIOUS

PDF

42.7 KB Authoring application: Adobe PDF Library 9.0
MD5: b3f9919b3ff2cc34749dadf0457d8db3 SHA-1: 82edddd387ec049b0d8b04b14451f03d16b0b617 SHA-256: f57cac7736241215fdbfe9d3e2129a7e1c9b437f6172035acbda314c1f39d4b6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to redirect users to malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URLs are the primary IOCs, suggesting a phishing or content redirection campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gazelleleadership.net/uploads/1/3/0/5/130543757/2061917.pdf
    • http://valuemanifesto.org/uploads/1/3/0/6/130621909/cbf91440e48647.pdf
    • http://mrsnicolas.com/uploads/1/3/0/7/130740141/5307354.pdf
    • http://drtoxie.com/uploads/1/3/0/2/130289431/sefij_mivedegasumoka_jifut.pdf
    • http://rac-ng.com/uploads/1/3/0/7/130738696/dac2ad8b91ca.pdf
    • http://www.vanity-fire.org/uploads/1/3/0/6/130639632/votudavux.pdf
    • http://www.valbarrartist.co.uk/uploads/1/3/0/4/130436089/1110992.pdf
    • http://oxnard-photography.com/uploads/1/3/0/4/130490421/02e62a708.pdf
    • http://hashaldi.store/uploads/1/3/0/3/130312980/9162757.pdf
    • http://jamicide.com/uploads/1/3/0/2/130288307/1940859.pdf
    • http://papomundo.org/uploads/1/3/0/5/130550754/1951825.pdf
    • http://apartmentlocatorshomefinding.com/uploads/1/3/0/7/130738525/5211615.pdf
    • http://spineandnerves.com/uploads/1/3/0/6/130640074/tinamu_larogifalom_wisadija_pexubuwudeb.pdf
    • http://oldtownimports.com/uploads/1/3/0/6/130604715/ximuguputegidoj_godojozojoduru_vupivuravit_verovebu.pdf
    • http://everybodylovesrita.com/uploads/1/3/0/6/130604197/3038285.pdf
    • http://geneticdetection.com/uploads/1/3/0/2/130289346/mijidixazora_pinabudifugigu_lomomi_jubomugeje.pdf
    • http://songofthelarkmusicforthesoul.com/uploads/1/3/0/5/130539370/b00cdc78e1a77c.pdf
    • http://ucddowntown.org/uploads/1/3/0/2/130287946/84e9f.pdf
    • http://knappd.net/uploads/1/3/0/6/130639358/7583380.pdf
    • http://fcayodemo.com/uploads/1/3/0/7/130738650/d111f5e1d0.pdf
    • http://shopwildflowercottage.com/uploads/1/3/0/4/130483325/983913.pdf
    • http://marchettispaghetti.com/uploads/1/3/0/6/130605116/nabidedenovek.pdf
    • http://thelookoutapartments.com/uploads/1/3/0/2/130289799/wekusuwujilimi.pdf
    • http://loansforsmallbusiness.co/uploads/1/3/0/7/130775411/widevidabejale.pdf
    • http://www.pcbchain.co.uk/uploads/1/3/0/8/130874239/130874239.html#ayatul+kursi+by+mishary
    • http://mrsnicolas.com/uploads/1/3/0/7/130740141/5307354

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000233f.bin
1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x233F 1388 bytes
font_01_sfnt_off00002a94.bin
fe757ca4cbe2cbecc3f9401ed977d5e0796092037bb3a54da32842f6b429d42d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A94 8088 bytes
font_02_sfnt_off00004277.bin
447e685abe7f1d46a0d0267b6834a6fb38c645b8bac472bab21068d93640b9bc
pdf-font-stream PDF embedded font (sfnt) at offset 0x4277 8020 bytes