Malicious PDF — malware analysis report

Static analysis result for SHA-256 23754f81c47a7025…

MALICIOUS

PDF

25.3 KB Authoring application: PDFBox
MD5: c6b094a787de784092e6f70d2659cf97 SHA-1: 7a088702d6e3691b9da7a2d71b350dbd97f36e83 SHA-256: 23754f81c47a7025a9eb5ab6880514cbd02305c41f73b5393bd39df69dac335c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file was detected by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0 and flagged by an ML classifier, indicating malicious intent. It contains multiple external URIs pointing to various PDF and HTML files hosted on different domains. These URLs are likely used to redirect users to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://sparxelectricalcontractors.com/uploads/1/3/0/5/130543377/bedadoni_vofixuneperul_rareg_lufirulube.pdf
    • http://thesociallubricant.co/uploads/1/3/0/4/130435531/a30b9.pdf
    • http://beingsemprendedores.com/uploads/1/3/0/2/130289344/6557833.pdf
    • http://nicollaslittleshop.com/uploads/1/3/0/6/130621490/sutidilejotatamu.pdf
    • http://benkregel.com/uploads/1/3/0/6/130620632/130620632.html#inquisitor+martyr+void+crusade+guide

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f9c.bin
0f5518ac02ce11a96c8a3cf0042f5bc43da1c7839a2bf03d1bb4fa0e3d710fd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xF9C 6556 bytes