Malicious PDF — malware analysis report

Static analysis result for SHA-256 5ada5074f23731c7…

MALICIOUS

PDF

44.8 KB Authoring application: OpenOffice Draw
MD5: 079e24f3dee2912a0272b3592c6c5a06 SHA-1: bec946408b05e9d95f4eeefa74ca4791247650e7 SHA-256: 5ada5074f23731c727370dfce08db9a339e0a15434ff1b5fea6209a521eca221
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains embedded URLs pointing to other PDF files and an HTML page, likely intended to trick users into downloading further malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically identified as phishing. The document body, though heavily obfuscated, suggests a lure related to 'Boyka full movies 2018'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://almahruqicars.com/uploads/1/3/0/6/130639269/e168506735d554.pdf
    • http://mijaliscogrill2.com/uploads/1/3/0/3/130313000/7806326.pdf
    • http://milexy.com/uploads/1/3/0/6/130620757/fe5279575e8ad9e.pdf
    • http://cfthomas.com/uploads/1/3/0/5/130551505/130551505.html#boyka+full+movies+2018
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000558f.bin
a99295a558c9f720e49e590ab74cb29c474d77edf6cc5de486cd3b14541749d3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x558F 25328 bytes
font_00_sfnt_off00000fff.bin
9b38992f1ea26e44a2f04d199fed970192fd08ae855d5c3d690ced96dac0e4ef
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFF 9908 bytes