Malicious PDF — malware analysis report

Static analysis result for SHA-256 f799cf94d5691b72…

MALICIOUS

PDF

33.7 KB Authoring application: LibreOffice
MD5: a50d6dbe4b2afc1bef99624f74d07295 SHA-1: e6d7ac313df141e43decf28360f41efe47e11e1a SHA-256: f799cf94d5691b72a09617910f1a71e876cedfea3ff88547107d6ef607631538
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic, which strongly suggests a phishing or SEO poisoning attack. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports this. The document body, though heavily obfuscated, contains fragments of URLs that align with the embedded link farm, indicating the primary purpose is to redirect users to malicious content hosted on external domains.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://2210enterprisedrive.com/uploads/1/3/0/6/130604289/digojorubokul_gilan_jimojuwe_vetujokijej.pdf
    • http://sotfgame.com/uploads/1/3/0/4/130483041/b36c81cf.pdf
    • http://inmyday.net/uploads/1/3/0/3/130323962/9779dc25e33.pdf
    • http://orbitfiction.net/uploads/1/3/0/5/130589045/1824e13a2d.pdf
    • http://municipalbondfraud.info/uploads/1/3/0/6/130620213/7785651.pdf
    • http://chores4sale.com/uploads/1/3/0/5/130550887/1b591c04451ef.pdf
    • http://127onyork.com/uploads/1/3/0/4/130489228/fowakegomagej-nufutedelowabu.pdf
    • http://justiceanddignity.org/uploads/1/3/0/6/130604940/mogaz-xasodera.pdf
    • http://m.kaltydesigns.com/uploads/1/3/0/4/130491850/f553507e61f93.pdf
    • http://ninistone.com/uploads/1/3/0/5/130551087/ed6bcd79135697f.pdf
    • http://aspenleafproductions.com/uploads/1/3/0/3/130323271/5653343.pdf
    • http://sales15-ip-phone.pleasingfood.com/uploads/1/3/0/8/130813756/130813756.html#basic+sentence+structure

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002d6d.bin
371b939d725ceb2750b97d280d8c6f5237c55cc205e92d793ec0f9066cf037fd
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D6D 7656 bytes