Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e4db9fc2a94260d…

MALICIOUS

PDF

37.3 KB Authoring application: QPDF
MD5: 32908ccf90d5b78280b0544660fc02a6 SHA-1: 860a5132b4792a589def07649976a61dda0a6cba SHA-256: 4e4db9fc2a94260d3e47a474017c038b6d9e99327680023c37cd49af925d1b34
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, specifically as a phishing PDF. The document body contains multiple URLs that likely serve as lures to download further malicious content. The presence of these external links strongly suggests a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://trafficlynx.com/uploads/1/3/0/7/130739499/veleji_livetu_zevuzipadumir_maxesaj.pdf
    • http://lumlatist.com/uploads/1/3/0/2/130291922/fuwet.pdf
    • http://tributetowomenmalaysia.com/uploads/1/3/0/6/130604654/sufelibedasowaw.pdf
    • http://juliejesternewman.com/uploads/1/3/0/7/130776269/130776269.html#gimme+gimme+gimme+similar+song

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011c0.bin
940ff81ad59c09c6edc10d317be20eb55ff3f8df097216929d36b876431b77dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C0 8596 bytes
font_01_sfnt_off0000402c.bin
378288d3133907284a1dd708aec606fa45674349f7e67e9eaedc79a8f6af9139
pdf-font-stream PDF embedded font (sfnt) at offset 0x402C 16228 bytes
font_02_sfnt_off0000551d.bin
4823f23e211945f0c8c4c24aaf9121222a0d32701ea66d5ed0d898bd5327f6c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x551D 2384 bytes