Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc4432250ef0e603…

MALICIOUS

PDF

51.5 KB Authoring application: Solid Converter PDF
MD5: 006d9fe14315f643ad409e63208b1c7a SHA-1: d6b26d6d6d6b5f9aedfed221b84c78ae963dae09 SHA-256: fc4432250ef0e60339620816a556ff53eb27b6d508e37e17e05f139ac229609e
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO spam or to distribute malicious payloads. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body itself is heavily corrupted and does not provide clear user-facing content, but the presence of numerous external links is the primary indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://allisongiessuebelhair.com/uploads/1/3/0/4/130436093/zifaxonul-pumewuparogimaw-jabebekokewune-mogosunipu.pdf
    • http://netwerkpijnrevalidatie.com/uploads/1/3/0/6/130621084/xasibusufokilagenalo.pdf
    • https://davukefofuj.weebly.com/uploads/1/3/0/4/130436152/3651531.pdf
    • http://lobeziboma.botanicart.ru/uploads/2020/01/27/591217.pdf
    • http://stxcleanse.com/uploads/1/3/0/5/130588195/zubufonefevolax-loxadobuwezo-tawetuxubepaji-tubolebifosaj.pdf
    • http://minnesotalashextensions.com/uploads/1/3/0/2/130289703/zutisorazinobar.pdf
    • http://nano.audiostart27.icu/uploads/2020/01/28/namiroruvu.pdf
    • http://biluwafumi.quran-media.online/uploads/2020/01/28/fodopepolenabeb.pdf
    • http://risechildrenschoir.org/uploads/1/3/0/3/130323285/lobegisulo.pdf
    • http://roj.lulacrib.com/uploads/2020/01/29/refajebaliwore-rexetem.pdf
    • https://gelulaxo.weebly.com/uploads/1/3/0/5/130550716/famivuj.pdf
    • http://lesimprimespersonnalises.com/uploads/1/3/0/5/130551581/biwegegagagolulu.pdf
    • https://tilezerufad.weebly.com/uploads/1/3/0/4/130489168/9986807.pdf
    • http://mmshop.club/uploads/1/3/0/4/130436450/lalab.pdf
    • http://motorolka.ru:80/uploads/2020/01/29/3198686.pdf
    • http://steamdiscoverylabbeta.com/uploads/1/3/0/6/130621385/9f7c140e0607.pdf
    • http://personalblogmadt.com/uploads/1/3/0/6/130603690/noxerusujapiwalapope.pdf
    • https://kunikowowumeba.weebly.com/uploads/1/3/0/2/130292110/6358503.pdf
    • http://spiritedquest-equine.com/uploads/1/3/0/6/130620880/kiferonufepefomen.pdf
    • http://dilev.ieltsjo.tech/uploads/2020/01/27/c3b28e7950327a.pdf
    • http://artbyvivi.com/uploads/1/3/0/6/130604631/kijikuminafit.pdf
    • http://greatertoukley.org/uploads/1/3/0/5/130590142/vugavoxo-winoji.pdf
    • http://hipsterleaks.com/uploads/1/3/0/5/130551714/vutep.pdf
    • http://advance-it.net/uploads/1/3/0/6/130639976/130639976.html#feelings+worksheet+1st+grade
    • https://kunikowowumeba.weebly.com/uploads/1/3/0/2/130292110/63

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011b7.bin
3631b19d8a3039cd4b512956d49ae8ffdaa4fd553ed7eb4ffb95a733ef95b133
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B7 8016 bytes