Malicious PDF — malware analysis report

Static analysis result for SHA-256 2663d7df2481d28d…

MALICIOUS

PDF

40.8 KB Authoring application: OpenOffice.org
MD5: 07d39f1dfa39191c996006501a6161cc SHA-1: 67101e552fa11d33994e4f5ae7273eb9b2ad51da SHA-256: 2663d7df2481d28d077647b2023c5fedadeda75de7016e6039ca15d2be819cdd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document that contains multiple embedded URLs pointing to other PDF files, suggesting a phishing or social engineering lure. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent. The document body, though partially corrupted, contains text related to legal terms and includes the malicious URLs, reinforcing the phishing pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pulquetour.com/uploads/1/3/0/2/130272296/doruvosupexo.pdf
    • http://406northvbclub.com/uploads/1/3/0/6/130620207/3a9642dc318.pdf
    • http://baobabtreestudio.net/uploads/1/3/0/5/130543035/634482348.pdf
    • http://bsa-sccc-pack301.com/uploads/1/3/0/5/130541133/130541133.html#ratio+decidendi+obiter+dicta+difference

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000fcc.bin
cc52f17e67174e588ca559b56c3f3a2c6041a789e4c585dbdb3296eff80a9fc5
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCC 8192 bytes
font_01_sfnt_off000059b8.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x59B8 16036 bytes