Malicious PDF — malware analysis report

Static analysis result for SHA-256 2225c9c6194eed8b…

MALICIOUS

PDF

42.7 KB Authoring application: Karbon
MD5: 1f8ee5d2413d060fbfa731ab68621c0a SHA-1: 09edd399cf194eab8d43f4507cff19a0b5f0f4b9 SHA-256: 2225c9c6194eed8b53ce7ea451aa087074750bcb7a71c22a9e31a7d3fee1f349
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document detected as malicious by ClamAV and an ML classifier. It contains multiple embedded URLs pointing to other PDF files, suggesting a phishing or social engineering lure. The document body, though partially obfuscated, contains text related to 'Amnistia internacional pena de muerte pdf', indicating an attempt to exploit interest in sensitive topics to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vehicleloanusa.com/uploads/1/3/0/4/130476207/5613859.pdf
    • http://neuropolisblog.com/uploads/1/3/0/4/130488213/5781835.pdf
    • http://mararet.music-kidskola.com/uploads/2020/01/28/garukobesa.pdf
    • http://relaxitswater.com/uploads/1/3/0/4/130489132/49ccd1b1.pdf
    • http://juliejesternewman.com/uploads/1/3/0/4/130435850/130435850.html#amnistia+internacional+pena+de+muerte+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010b8.bin
f6e85604c9520bb9eb4e125efaefae3ff0e649673cec90b03d56f02591b4e90c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B8 10192 bytes