Malicious PDF — malware analysis report

Static analysis result for SHA-256 631c49c4f43481e6…

MALICIOUS

PDF

29.8 KB Authoring application: SWFTools
MD5: dbc0aecb3ae85dfd063e302cc46335fa SHA-1: 0c9caf99173406b869244bbd5fc07d0b187d1fc2 SHA-256: 631c49c4f43481e696462d0b4fca0bfbdbca4a9d5a6b11b7525763d50b342d91
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains embedded URLs pointing to other PDF files and an HTML file. The document body, though partially corrupted, suggests a lure related to a book preview, aiming to trick users into clicking the malicious links. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://reliabletrust-translations.com/uploads/1/3/0/2/130270994/a8064f58065.pdf
    • http://bluecubeworkshop.com/uploads/1/3/0/2/130273625/9164048.pdf
    • http://ofnol.com/uploads/1/3/0/2/130291766/9993005.pdf
    • http://umsegundoantesdevocemorrer.net/uploads/1/3/0/6/130620305/c2970.pdf
    • http://westendbarbershop.com/uploads/1/3/0/7/130740073/potetak-tediwitixaba-suxovufeli.pdf
    • http://b4bigschool.com/uploads/1/3/0/7/130739454/130739454.html#libro+los+7+habitos+de+los+adolescen

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000107d.bin
6e024e1581ab15c0184a3e5609a3d1f34dcb5eb4db39a6fd8be1dab3baf6559b
pdf-font-stream PDF embedded font (sfnt) at offset 0x107D 8024 bytes