Malicious PDF — malware analysis report

Static analysis result for SHA-256 3884ad779d40b6cc…

MALICIOUS

PDF

32.1 KB Authoring application: SWFTools
MD5: a6b8e2b33c9070d02a4cb52695cef094 SHA-1: 223a749fb54e77f42855a8f7360e61a84cfe0c24 SHA-256: 3884ad779d40b6ccc5d63eff68e924f13ac3bcabbad2c33fc67b95a695228150
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF containing multiple embedded URLs that lead to other PDF or HTML files. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent, likely phishing or malware distribution. The document body, though partially corrupted, mentions 'Read a clockwork orange online pdf' and includes URLs, suggesting a lure to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wajase.mactak.center/uploads/2020/01/27/7277261.pdf
    • http://zonaspasalon.ru/uploads/2020/01/28/vusewozaxo-remimotigutamen.pdf
    • http://therhinestoneanchor.com/uploads/1/3/0/5/130545698/872563.pdf
    • http://rasixamig.gosuslugi-moskva.ru/uploads/2020/01/29/aca9a1ad76d9.pdf
    • http://vutis.aktivators-windows10.ru/uploads/2020/01/28/2377624.pdf
    • http://sauerlandhypotheek.nl/uploads/1/3/0/3/130324206/130324206.html#read+a+clockwork+orange+online+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000106b.bin
e26110687b73dbbcd61a173ed85b11d1b4a6d19a282fe8a3dc61f69a8ec4f5fd
pdf-font-stream PDF embedded font (sfnt) at offset 0x106B 7940 bytes