Malicious PDF — malware analysis report

Static analysis result for SHA-256 61bf5379cc6f6574…

MALICIOUS

PDF

39.2 KB Authoring application: GIMP
MD5: 8d872384dbc664c7e387adfbe1984672 SHA-1: 2802b630a28d0e3d43ad3ed2d0c52257b120a2a9 SHA-256: 61bf5379cc6f6574c3a8dbad4ec447dd7fbda6c9335f1a39cc967fa489fc02d2
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by multiple heuristics as malicious, including a ClamAV detection for 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. It contains embedded URLs pointing to other PDF files, suggesting a phishing or malware distribution scheme. The document body, though partially corrupted, mentions 'Kerboodle answers french foundation', likely a lure to entice users to download the linked malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mkwpartners.com/uploads/1/3/0/5/130590416/7371523.pdf
    • http://yippeewebdesign.com/uploads/1/3/0/2/130270957/4b70b3c65.pdf
    • http://dodi.alcoprofi.com/uploads/2020/01/29/6793975684.pdf
    • http://lindatownshend.com/uploads/1/3/0/4/130488509/tobeseruv_wisas_viriweboretabi.pdf
    • http://mikeintucson.com/uploads/1/3/0/5/130589208/130589208.html#kerboodle+answers+french+foundation

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001068.bin
6175fe6d7c284717d7c9af0cc2da6f061cf7f211316f6312258df96a215c7866
pdf-font-stream PDF embedded font (sfnt) at offset 0x1068 9044 bytes