Malicious PDF — malware analysis report

Static analysis result for SHA-256 fef82c703fef2559…

MALICIOUS

PDF

41.9 KB Authoring application: Pdftk
MD5: 83f5fe277480d71a3341ef202ce34f1f SHA-1: d33784f1699bfad7e62045bbdaf16da158e1b46a SHA-256: fef82c703fef25597765776091d6f6dd4d749d3274683110210f84effcee5845
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a mass external link farm, with multiple URLs pointing to seemingly unrelated PDF documents, disguised under the pretext of an internship cover letter. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection intent. The embedded URLs are the primary indicators of compromise, likely leading to further malicious content or exploitation.

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://happyvids.com/uploads/1/3/0/3/130313324/6291674.pdf
    • http://pacesettersinstitute.com/uploads/1/3/0/6/130620928/d47bdcc2c3a25ee.pdf
    • http://allsaintsws.net/uploads/1/3/0/5/130542935/014de3e1fbfe0.pdf
    • http://tahoegoogletours.com/uploads/1/3/0/5/130589077/130589077.html#cover+letter+architecture+student+internship

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000103a.bin
fcf409b7aefea2e5f10fee5d1246df6d03a0ed4fe3d8f739fdb6725b833139b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x103A 9572 bytes