Malicious PDF — malware analysis report

Static analysis result for SHA-256 6df48c1956e66fb9…

MALICIOUS

PDF

42.0 KB Authoring application: pdf-parser
MD5: 0d7368fe972294d48707f39897881181 SHA-1: 76520efbd32e81c4e5fee0db1f6ae47e9fd76457 SHA-256: 6df48c1956e66fb97141188185e769c28fe36042626348d2f188e98a4f0d8439
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing-related PDF. It contains multiple embedded URLs that likely lead to further malicious content, suggesting an attempt to trick users into downloading additional malware. The presence of external URI indicators further supports this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mrelectricalservices.com.au/uploads/1/3/0/2/130272905/3268553.pdf
    • http://attorneyfloridaprobate.net/uploads/1/3/0/7/130739653/xubumofoja-kaxibasiga-gimorujojiwali-sovude.pdf
    • http://lucky13lawncare.com/uploads/1/3/0/6/130621458/xisag_xuzotifupaval.pdf
    • http://demipifax.kuhni-msc006.icu/uploads/2020/01/28/5850771.pdf
    • http://dobryakkot.site/uploads/1/3/0/5/130539913/7f301.pdf
    • http://mindforyou.org/uploads/1/3/0/2/130272955/130272955.html#topology+project+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012a4.bin
07c84b802108a03821125455ce0fdfe194fc580ccfb5ad0ad6e99804e4a98ffa
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A4 9012 bytes
font_01_sfnt_off00006a4f.bin
83459e82cebe561b9e65dda6a09953c9e35f75e5df0fa62a624e1833cc5b8086
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A4F 1708 bytes