Malicious PDF — malware analysis report

Static analysis result for SHA-256 f81b8aca46670949…

MALICIOUS

PDF

74.4 KB Authoring application: OpenOffice.org
MD5: 86eb52f9630d5498bf474f7ad927d337 SHA-1: b07026af15c7059248be72c7d0df73e9c6390685 SHA-256: f81b8aca46670949e1900f9d67f4e69da95f7c9182f9102d8b7bb85d9388a97c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was identified as malicious by ClamAV with the signature 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. Static analysis revealed a large number of embedded external links, forming a link farm. The primary heuristic 'PDF_SEO_LINK_FARM' indicates that these links are likely intended to direct users to malicious content or phishing sites. The document body contains garbled text, suggesting it is not intended for direct user consumption but rather as a container for the malicious links.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://josephanspach.com/uploads/1/3/0/6/130604580/wuvotiz.pdf
    • http://preludetoaction.com/uploads/1/3/0/3/130313463/109e4f626b29d.pdf
    • http://www.shop.daisyalexandriadesigns.com/uploads/1/3/0/5/130588724/8814092.pdf
    • http://fdaauditor.com/uploads/1/3/0/2/130288600/xitud.pdf
    • http://ecuoutlet.com/uploads/1/3/0/7/130739517/xibug-sapudivegaz-mewimegiwakafo.pdf
    • http://moederfamily.com/uploads/1/3/0/2/130270985/e40d0eb389.pdf
    • http://www.matchamade.com/uploads/1/3/0/9/130969862/kikarej-sateguzisefa-finak-dugeleko.pdf
    • http://innovativesportfans.net/uploads/1/3/0/2/130274097/8c0ad79d0faba.pdf
    • http://seasonedservices.com/uploads/1/3/0/5/130550882/2a581658624c.pdf
    • http://searchornurture.com/uploads/1/3/0/4/130435755/fujedizasef.pdf
    • http://engenhoca.mobi/uploads/1/3/0/6/130620519/7cab3b8.pdf
    • http://heygirlglam.com/uploads/1/3/0/2/130289481/7117552.pdf
    • http://www.neslle.com/uploads/1/3/0/6/130640229/2643208.pdf
    • http://50statesofjesus.com/uploads/1/3/0/5/130539843/2245601.pdf
    • http://airoparkourfreerun.com/uploads/1/3/0/2/130270986/jilofimosepe-vubej.pdf
    • http://bridgecitygraphics.net/uploads/1/3/0/5/130543279/fiwodila.pdf
    • http://hendersonsboysgame.com/uploads/1/3/0/6/130604034/3b86bb9262ae41.pdf
    • http://school-playground-equipment.com/uploads/1/3/0/5/130539247/a54a13bcb09c10.pdf
    • http://sligergames.com/uploads/1/3/0/2/130272325/duzozameludep_vanupanububozuk_nenududo_xibevakukexazif.pdf
    • http://ingecos.com/uploads/1/3/0/5/130590432/4679824.pdf
    • http://drvnotfix.com/uploads/1/3/0/4/130489363/1e714447.pdf
    • http://marlinjames.net/uploads/1/3/0/4/130435960/55305b5f29a.pdf
    • http://mingyiliu.me/uploads/1/3/0/5/130589998/3628937.pdf
    • http://mrsmauck.com/uploads/1/3/0/2/130289495/8427209.pdf
    • http://ntxsportswear.com/uploads/1/3/0/6/130621832/verolo-xugud-todotanisojut.pdf
    • http://schellekens.ca/uploads/1/3/0/2/130288592/130288592.html#unilateral+right+pleural+effusion+radiology
    • http://sligergames.com/uploads/1/3/0/2/130272325/duzozameludep_vanupanububozuk_nen

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000017af.bin
54846c2477883277887bdd74107e16d9e773cee02ce3fc9543d2bf2d1d487df5
pdf-font-stream PDF embedded font (sfnt) at offset 0x17AF 7968 bytes
font_01_sfnt_off0000d4f8.bin
1110447959503c75238c0f1bcdf9de7fad567fc767730a4530dcb0d3a64541bd
pdf-font-stream PDF embedded font (sfnt) at offset 0xD4F8 2696 bytes
font_02_sfnt_off0000dddc.bin
b3affdfdfee497c2d3230853582529cf395d265bfdbb8cde7d84ae9c33602211
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDDC 16036 bytes