Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6c7c5d308049542…

MALICIOUS

PDF

28.7 KB Authoring application: OpenOffice.org
MD5: 0c311130ac6906b8a17489dfef182ece SHA-1: be9a2ec37748dfd552cbca2a8e28ed0a91acbf3e SHA-256: f6c7c5d308049542b147df7b834b9f816cfb30238dc8003728d96ccda4d73f69
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs pointing to other PDF files, indicating a link farm or a distribution mechanism for further malicious content. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier's high confidence score further support its malicious nature. The document body text is largely unreadable due to encoding issues, but the presence of external links is the primary indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://coralcoastbookkeeping.net/uploads/1/3/0/2/130273617/lagagofixa_viranusezekujo_xuwubofar_vefajejefirazo.pdf
    • http://friend-vibes.com/uploads/1/3/0/4/130488884/5494588.pdf
    • http://sandiegosuperlawyers.com/uploads/1/3/0/3/130379681/2397513.pdf
    • http://revivereading.com/uploads/1/3/0/6/130604756/2622544.pdf
    • http://ivcbrighton.com/uploads/1/3/0/7/130740163/naperugifu-finefuriso-rimapiden.pdf
    • http://sweetestdreams.org/uploads/1/3/0/6/130604801/silakesiramawu.pdf
    • http://13conversations.org/uploads/1/3/0/5/130552016/vazumobiwizunonaje.pdf
    • http://puppylovepetcarema.com/uploads/1/3/0/4/130483616/af25b.pdf
    • http://bigmindbigsoul.com/uploads/1/3/0/5/130539049/rivegivedugoboj.pdf
    • http://roswellwaterproofing.com/uploads/1/3/0/7/130775498/lujegime.pdf
    • http://edtnetworks.com/uploads/1/3/0/6/130620251/6671423.pdf
    • http://ywbhe.bpmtc.com/uploads/1/3/0/3/130323173/130323173.html#9th+math+all+formula+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001903.bin
6b8e1a4c16af451a51601807b450326c2670d8b67a6dd4f6a90662cfb2eed91d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1903 7660 bytes