Malicious PDF — malware analysis report

Static analysis result for SHA-256 f79895e944ebc73e…

MALICIOUS

PDF

37.0 KB Authoring application: Smallpdf Desktop
MD5: 4cb66d7a1b11d7f711093c2c5f0cc2c2 SHA-1: 1ca810efe63c0ef593f600af463781df1b523b18 SHA-256: f79895e944ebc73e03f208319b084aef36a42b96ed558585cc465096e9831e06
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file exhibits a 'link farm' pattern, embedding a large number of external URLs. This technique is commonly used in phishing campaigns to direct users to malicious sites. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports the phishing and redirection intent. No scripts were extracted from this sample, and the document body content is largely unreadable, making the URL analysis the primary indicator of malicious activity.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://nolancunningham.net/uploads/1/3/0/6/130639851/ca10c2cf74.pdf
    • http://namalitainternational.net/uploads/1/3/0/4/130483741/vakidifuwidop_zowisired_kedobikuti_wejukebalisige.pdf
    • http://saharaexchange.com/uploads/1/3/0/5/130552017/d3957.pdf
    • http://walkercriminallawyers.com/uploads/1/3/0/2/130288378/0de156.pdf
    • http://theorderoftheoak.org/uploads/1/3/0/7/130739285/3b0328e19846df.pdf
    • http://gonzosautotronicdiagnosticcenter.org/uploads/1/3/0/5/130551311/a734a41a093635.pdf
    • http://www.liventertainmentproductions.com/uploads/1/3/0/3/130323477/8199009.pdf
    • http://damiangorman.com/uploads/1/3/0/6/130621267/6379478.pdf
    • http://cookinglivinggiving.com/uploads/1/3/0/5/130551526/janede_nimenupuxuz_razat.pdf
    • http://bdaglobal.net/uploads/1/3/0/7/130776393/jipuniru-vamobedexux.pdf
    • http://hanurl.com/uploads/1/3/0/8/130874359/45a74db87507.pdf
    • http://onestoptoolshop.shop/uploads/1/3/0/5/130588594/7956986.pdf
    • http://outdoorgamesatnight.com/uploads/1/3/0/3/130313127/jexisexogujut_vojira.pdf
    • http://yellowpencilrental.com/uploads/1/3/0/9/130969375/bifafesitabew-sokotakiwa-dupufibijiro-vedulawiwi.pdf
    • http://webdisk.anitacoaching.com/uploads/1/3/0/6/130604621/731739.pdf
    • http://singaporenewexecutivecondo.com/uploads/1/3/0/6/130604254/7840a14612f6.pdf
    • http://nfctigers.com/uploads/1/3/0/4/130476678/e27bd850d.pdf
    • http://insuranceexecutive.net/uploads/1/3/0/4/130476148/39b3ff491f.pdf
    • http://commongroundsphilly.com/uploads/1/3/0/5/130540897/redixejap.pdf
    • http://amyweatherman.com/uploads/1/3/0/6/130620966/gaxun.pdf
    • http://culbertsonandcompany.com/uploads/1/3/0/4/130483830/9806767.pdf
    • http://ezstudentloanlawyer.com/uploads/1/3/0/2/130272356/domuv_lepet.pdf
    • http://littlecountrygreenhouse.net/uploads/1/3/0/4/130483756/bedos_debebolan_fapuruwelajam_zuvofonusabag.pdf
    • http://stevenmatos.studio/uploads/1/3/0/4/130435794/9721099.pdf
    • http://mshvita.com/uploads/1/3/0/5/130546153/9469674.pdf
    • http://taojinyingkaihushouxuanhailifang.br3h.com/uploads/1/3/0/2/130289711/130289711.html#morricone+cinema+paradiso+piano
    • http://culbertsonandcompany.com/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002dd6.bin
c199be92cc918e98b1c70dd1cbfedb6efd737fa2f10e3f2ad86b86a5e6490708
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DD6 7216 bytes