Malicious PDF — malware analysis report

Static analysis result for SHA-256 fad4c4781da564f9…

MALICIOUS

PDF

32.6 KB Authoring application: Inkscape
MD5: f2935201d87adafc5615fb5f8cea5def SHA-1: d115fdc0695f9ba5d1a2f52f4f6352a527dba774 SHA-256: fad4c4781da564f9563af1bbdce787bed2f0d9c5f2c5835620465834ca03eeae
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body, though heavily obfuscated, appears to be a lure for educational materials, which is a common tactic for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://speakup.london/uploads/1/3/0/7/130738924/xujipezagefoxo_ruvokogi.pdf
    • http://www.goldencircleent.com/uploads/1/3/0/5/130543682/5122464.pdf
    • http://dieselmagic.net/uploads/1/3/0/8/130874261/c5f60526.pdf
    • http://thekookas.com/uploads/1/3/0/7/130739232/4531573.pdf
    • http://www.bextraordinaire.com/uploads/1/3/0/8/130814717/xavobus.pdf
    • http://www.createdesignrestore.com/uploads/1/3/0/2/130288630/af28e320af4a.pdf
    • http://shoppivotalchocolates.com/uploads/1/3/0/7/130775203/9889243.pdf
    • http://thenewblueworld.com/uploads/1/3/0/7/130775478/8160787.pdf
    • http://hostmaster.gastrokidzz.ch/uploads/1/3/0/5/130589050/gonujej_fuwisib.pdf
    • http://pbcdac.com/uploads/1/3/0/7/130776275/dipig.pdf
    • http://cruisecrtl.com/uploads/1/3/0/4/130435697/4605072.pdf
    • http://getpinbox.com/uploads/1/3/0/3/130379141/3a9d1c.pdf
    • http://zealgum.com/uploads/1/3/0/6/130640190/fozes.pdf
    • http://ourchildrensfund.com/uploads/1/3/0/5/130551718/f95b21a9e.pdf
    • http://mail.norcalconcrete.com/uploads/1/3/0/6/130603760/60183ef4246.pdf
    • http://besmokefree.co.nz/uploads/1/3/0/4/130436451/2d8903ce811fa.pdf
    • http://iamtaylor.net/uploads/1/3/0/6/130639784/5b6e8df76.pdf
    • http://one-heart-one-soul.org/uploads/1/3/0/2/130274241/1c0727.pdf
    • http://alpha.withcarry.com/uploads/1/3/0/9/130969298/xumemote-suzutepate-vupobefiduj-zagifob.pdf
    • http://matthewbrooke.com/uploads/1/3/0/6/130639244/gapivagonivok.pdf
    • http://gifsagainsthumanity.com/uploads/1/3/0/4/130491001/39cc29f.pdf
    • http://steelbullets.com/uploads/1/3/0/4/130483402/3210739.pdf
    • http://host12.pleasingfood.com/uploads/1/3/0/7/130740244/130740244.html#pre+algebra+math+packet+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001e0c.bin
d88df3206c15462b72dc1afd9b5a4dc7b34350167a2de665e8dc2e1dfbb16ffb
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E0C 7844 bytes