Malicious PDF — malware analysis report

Static analysis result for SHA-256 76d47d0ba0146ce3…

MALICIOUS

PDF

38.5 KB Authoring application: PDFBox
MD5: d8e84740bc2236745508013254658849 SHA-1: e4e8db9f8c8cf9bfda59e9372ae6051dcb84a39a SHA-256: 76d47d0ba0146ce337df0916703ab3d8fe5b7e12cdd61b00e8b1bf9b31f2e0fd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document that contains multiple embedded URLs, several of which are flagged as unknown or malicious. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body itself contains references to these URLs, suggesting a phishing or malware distribution lure. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://kexo.globewebguru.com/uploads/2020/01/27/8810496.pdf
    • http://mokamevuf.picsonair.com/uploads/2020/01/29/ziselavelim_gamegiropovewa.pdf
    • https://fexazezi.weebly.com/uploads/1/3/0/2/130289662/8683397.pdf
    • http://utpgroupservices.com/uploads/1/3/0/5/130551135/dujone.pdf
    • http://mifanu.ecokzn.com/uploads/2020/01/27/nugiwuwijutewoz.pdf
    • http://iweargreatness.com/uploads/1/3/0/4/130478663/130478663.html#state+of+blockchain+q1+2018+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001083.bin
9777939500e930106a1fbcaccfd2769cf907efd69c62f4cd72289022d2e4f60d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1083 8432 bytes
font_01_sfnt_off00004f4d.bin
5d7ebd720715cd86529581f1d40cc643f68465477bd430d4be5ff736bc95f798
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F4D 16268 bytes