Malicious PDF — malware analysis report

Static analysis result for SHA-256 40cdeb4bab9b9c29…

MALICIOUS

PDF

35.5 KB Authoring application: Solid Converter PDF First seen: 2020-09-24
MD5: 449436cf49e9b89bccd87cc01b7fb34a SHA-1: ad25c74184267bd052cb138ceec7c17cc62a85c6 SHA-256: 40cdeb4bab9b9c29be6180bb716e19ac3f78719436362eb88e7849fcdcef25f4
114 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains multiple embedded URLs that are flagged as suspicious. The heuristic SE_CALLBACK_LURE indicates the document's content is designed to trick users into calling a phone number for fraudulent purposes, consistent with phishing or tech-support scams. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing campaigns.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://x-staticapolefitness.com/uploads/1/3/0/6/130639990/2c1a8f56.pdf PDF link annotation
    • http://montcoglass.com/uploads/1/3/0/2/130289311/gowolojekaragux_muzododozeto_zajujirewex.pdfIn PDF document text
    • http://spreadbitcoins.com/uploads/1/3/0/2/130273842/1247616.pdfIn PDF document text
    • http://blockchainambassador.ca/uploads/1/3/0/2/130272482/130272482.html#gta+5+money+cheat+xbox+360+story+modeIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000101d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x101D 8428 bytes
SHA-256: e47b71abb42a508d764a972a999727ce36b9f9486b3c2ece2e2b4fb6244b159d