Malicious PDF — malware analysis report

Static analysis result for SHA-256 12abc9e7a4921883…

MALICIOUS

PDF

37.1 KB Authoring application: Solid Converter PDF
MD5: 4b05c31dcb336f2e72023051f01c21ed SHA-1: 100def174f22fcef62d4442f6929b2dec370ca29 SHA-256: 12abc9e7a49218831f3ae5429039bb25003bdf02724e8fdfba34ab224b318692
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing embedded URLs that lead to potentially malicious content, as indicated by ClamAV and ML heuristics. The document body, despite being heavily obfuscated, contains references to URLs and mentions 'Solid Converter PDF', suggesting it's a crafted document. The embedded URLs are likely intended to redirect the user to download further malicious payloads or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://konogaj.jitoli.icu/uploads/2020/01/27/80b0f0a065.pdf
    • http://porterforcanton.com/uploads/1/3/0/3/130323250/e7658200e.pdf
    • http://nirvanacreations.weebly.com/uploads/1/3/0/6/130603917/suzisolava.pdf
    • http://mercigifts.ca/uploads/1/3/0/5/130539554/tekonitu.pdf
    • http://nekimastrategies.com/uploads/1/3/0/5/130539215/dirogi-vazupa-lilimowekok-movilidigokumi.pdf
    • http://colddiamnd.com/uploads/1/3/0/3/130313539/130313539.html#petite+formal+dresses+for+wedding+guest

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010d0.bin
d0c9b147666afa792db83e465cacff836c489d61789e22320d862d183092d439
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D0 8392 bytes