Malicious PDF — malware analysis report

Static analysis result for SHA-256 3dfd94f13978d330…

MALICIOUS

PDF

43.6 KB Authoring application: Scribus
MD5: f977fc829b7e70d6d5739c6f56a85f5c SHA-1: e2945c0a1c33747f017e9691d879cc2bb1b33d39 SHA-256: 3dfd94f13978d330ca82b1184265f68e0e909ff37d17ab6c1cc19fd3176229ab
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is a PDF document that contains embedded URLs. The ClamAV heuristic and ML classifier strongly indicate maliciousness, specifically identified as phishing. The document body, though heavily obfuscated, contains URLs that likely lead to further malicious content, such as other PDFs or HTML files, consistent with a phishing or malware distribution scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://obedientsoftware.com/uploads/1/3/0/6/130604456/67f046f54167d47.pdf
    • http://drtheresadobson.com/uploads/1/3/0/5/130550713/wewinedulowukomi.pdf
    • http://dossys.com/uploads/1/3/0/3/130312952/didosu.pdf
    • http://cityonloc.com/uploads/1/3/0/7/130739669/130739669.html#conical+pendulum+velocity+equation

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000116d.bin
2c9beb99250f057ba7e37664c88e4b0df8cbec60060d1cf738ca4e8b1a311685
pdf-font-stream PDF embedded font (sfnt) at offset 0x116D 8168 bytes
font_01_sfnt_off00006dc8.bin
d2147f0437fb95d6ecf9e3695a1a7b513ba0cafdf10a32261a90d4b966c7877e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DC8 3424 bytes