Malicious PDF — malware analysis report

Static analysis result for SHA-256 6ee2524eee58ba7b…

MALICIOUS

PDF

41.9 KB Authoring application: OpenOffice.org
MD5: 4757782c1ac4bc9d6b4b8a7f4aa6a981 SHA-1: c93f8ed2597da8b2f273cf49a66ee0805886a2b9 SHA-256: 6ee2524eee58ba7bd019afbc79a6f3f547c1cb67e79a92008769e1cbb208e141
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains embedded URLs pointing to other PDFs and an HTML file, suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware installation. The document body, though truncated, mentions 'Energia eólica como funciona pdf' and presents itself as a preview, aiming to trick users into downloading the linked malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pozasope.weebly.com/uploads/1/3/0/2/130288589/1958465.pdf
    • http://ashleynboyd.com/uploads/1/3/0/6/130621406/dumovikoxirip.pdf
    • http://cci-forum.com/uploads/1/3/0/7/130738799/pilabamifikog.pdf
    • http://obrothersdetailing.com/uploads/1/3/0/2/130271165/rudogisipepori.pdf
    • http://colddiamnd.com/uploads/1/3/0/2/130270796/130270796.html#energia+e%C3%B3lica+como+funciona+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010c5.bin
46dfe3dd8cd30baf0e6b2cf7b981aa153c0d1fc543613cfc903138fc9e182f09
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C5 10900 bytes