Malicious PDF — malware analysis report

Static analysis result for SHA-256 37323355e8a38173…

MALICIOUS

PDF

43.2 KB Authoring application: LibreOffice
MD5: dc23fad91181a8dc69207e8c48fc67c4 SHA-1: 51fd39d7d6b4506d42b436bce0fd518450eb7188 SHA-256: 37323355e8a381735143d8cab5f94a94b97e16690d8fd94fe17db500fdcc3e76
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains multiple embedded URLs that point to external PDF files, indicating a phishing or malware distribution attempt. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly suggest malicious intent. The document body, while containing unrelated text, also includes some of these URLs, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://downsideupphoto.com/uploads/1/3/0/3/130323115/2817485.pdf
    • http://lesa.bz/uploads/1/3/0/3/130313103/mewamirutar.pdf
    • http://mentorherbizmembership.com/uploads/1/3/0/4/130476511/dojasug.pdf
    • http://e2bioconsults.com/uploads/1/3/0/6/130639558/mukijapuwopad.pdf
    • http://thehnossaproject.com/uploads/1/3/0/6/130620272/130620272.html#ro+m+eternal+love+leveling+guide

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001062.bin
a81cd1129bcec0d6e9d01e811d7574df48ae864f340ff267f45be40f44c4be43
pdf-font-stream PDF embedded font (sfnt) at offset 0x1062 8932 bytes
font_01_sfnt_off00006dd9.bin
8ec8c2252d1b0a1cc16637c0e1f77da7137146423e231c53be47bbaf832064ce
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DD9 2048 bytes