Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ce2ded31614f067…

MALICIOUS

PDF

46.0 KB Authoring application: Pdftk
MD5: beccc140da974d9e8dcf4447de9a3187 SHA-1: 4bdb897f73ca9b2f74a1efb5f1e76c1be319a814 SHA-256: 3ce2ded31614f067072209971c2edaaf5543ee2c2516a2850982bf207437fca6
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains multiple embedded URLs that are likely used for phishing or to deliver further malicious content. The document body itself contains these URLs, suggesting a social engineering lure to trick users into clicking them. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fuckcharucki.com/uploads/1/3/0/5/130588389/xasikuxomilikezopux.pdf
    • http://movieseaon.com/uploads/1/3/0/6/130621072/lefufaxuro.pdf
    • http://muslyr.net/uploads/1/3/0/5/130551338/gozivimabewa-gozemumalakus-zorod.pdf
    • http://greenwolfverticalfarm.com/uploads/1/3/0/6/130621432/tedavevigipu.pdf
    • http://beautyflower.info/uploads/1/3/0/5/130550910/fidijemi.pdf
    • http://multistreams.com/uploads/1/3/0/7/130740112/130740112.html#sap+hana+migration+steps

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011fc.bin
095eea067325a4ce694d5efb431f8e2c581d3a64166b78fba90845d96f1e4448
pdf-font-stream PDF embedded font (sfnt) at offset 0x11FC 8116 bytes
font_01_sfnt_off00006d12.bin
5d7ebd720715cd86529581f1d40cc643f68465477bd430d4be5ff736bc95f798
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D12 16268 bytes