Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a7825dfb8162874…

MALICIOUS

PDF

32.7 KB Authoring application: LibreOffice Draw
MD5: 247c3de7ceaa34813b0abc29c38ae6a6 SHA-1: 3f272427ac3e51b5ff1507c7aaf50897d2bd6a8e SHA-256: 0a7825dfb816287460ceff9347075af525060bc04325e08b041d64f643d6233b
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs that likely lead to malicious content, as indicated by the ClamAV detection and ML classifier. The document body, despite being heavily obfuscated, contains references to 'Tamil audio songs' and several URLs, suggesting a lure to download further malicious files. The presence of external URI heuristics further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://axar-cars.com/uploads/1/3/0/5/130550654/kaviniwazowumow.pdf
    • http://podivul.coin-fishing.fun/uploads/2020/01/28/wifofan-xuvul.pdf
    • http://tenobu.myalbumsexy.com/uploads/2020/01/29/vezitapejawusifo.pdf
    • http://socalseas.com/uploads/1/3/0/4/130488157/1274935.pdf
    • https://misobebetolezur.weebly.com/uploads/1/3/0/5/130588966/pegewozo_wokobagitanek_tatabelix_dusunanivoluk.pdf
    • http://nupelicanparty.org/uploads/1/3/0/5/130551765/130551765.html#tamil+audio+songs++please

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010e3.bin
bb6ae919afe67b2fe556b73495dfc5f484316e21bc2e1591f0eaac1c36553f2a
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E3 8780 bytes