PDF static analysis report

Static analysis result for SHA-256 7831ab5ec03240ef…

SUSPICIOUS

PDF

575.0 KB Created: 2009-04-07 11:32:57 -04:00 Authoring application: LaTeX with hyperref package (via pdfTeX-1.40.3) First seen: 2018-10-07
MD5: e616e0a66493bcd40b1638a14fef31d1 SHA-1: f8a75fd1a6222eb11119b529b5abdeb9ace7230d SHA-256: 7831ab5ec03240ef0a3c09f617ea1547b189e27d672fddd7eca6f1e8ce977b0b
44 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The primary heuristic indicates a ClickFix social engineering attack, where the document prompts the user to manually execute a command. While many URLs are benign, two are marked as unknown, suggesting potential C2 or download infrastructure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier clean score 0.0025

Heuristics 3

  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://mielke.cc/brltty/ In PDF document text
    • http://mielke.cc/brltty/releases/In PDF document text
    • http://bugzilla.gnome.org/buglist.cgi?query=product:orca+In PDF document text
    • http://bugzilla.gnome.orgIn PDF document text
    • http://developer.gnome.org/tools/svn.htmlIn PDF document text
    • http://mail.gnome.org/mailman/listinfo/orca-listIn PDF document text
    • http://mail.gnome.org/archives/orca-listIn PDF document text
    • http://l10n.gnome.org/teamsIn PDF document text
    • http://l10n.gnome.org/module/orcaIn PDF document text
    • http://live.gnome.org/Orca/Braille#BrailleIn PDF document text
    • http://library.gnome.org/users/user-guide/stable/shortcuts-global.html.enIn PDF document text
    • http://bugzilla.gnome.org/show_bug.cgi?id=548169In PDF document text
    • http://pfaedit.sf.net/In PDF document text

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_086_off00062ee9.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x62EE9 21739 bytes
SHA-256: 9143d5c6371d54f01c98864c692cc15bf25a5bb4eae54031307b5213ae9e4711
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
font_00_type1_off0004d704.bin pdf-font-stream PDF embedded font (type1) at offset 0x4D704 1476 bytes
SHA-256: f41f89a5a793184868e4cd1985ff0c150cb4a00d90304179316be0d81dba5403
font_01_type1_off0004dd3c.bin pdf-font-stream PDF embedded font (type1) at offset 0x4DD3C 14228 bytes
SHA-256: 11cbe6479868509e3493465689d5d5d6fae7d2dbc71fb8aaeb21d737e47c923f
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.92, consistent with packed or encrypted content.
font_02_type1_off0005139f.bin pdf-font-stream PDF embedded font (type1) at offset 0x5139F 16469 bytes
SHA-256: c2d952cc9773db5bfedb254540728d961707cde6ff51c8520eaaef65d278fa46
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.
font_03_type1_off00055319.bin pdf-font-stream PDF embedded font (type1) at offset 0x55319 4848 bytes
SHA-256: ec42cf910fa8626b316ad94e8f1be5085504186df09b6027bf9f78fca1436430
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.53, consistent with packed or encrypted content.
font_04_type1_off00056438.bin pdf-font-stream PDF embedded font (type1) at offset 0x56438 13489 bytes
SHA-256: a2647632d9bad114531ee14d15c16c22f1b97ccbe9da99f242bdadcb53329ffc
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.91, consistent with packed or encrypted content.
font_05_type1_off00059827.bin pdf-font-stream PDF embedded font (type1) at offset 0x59827 11354 bytes
SHA-256: ce1ecf9505ca71de45fc67b184dae00bd3cd7adb5241ab44376c7ed945c9b05f
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
font_06_type1_off0005c570.bin pdf-font-stream PDF embedded font (type1) at offset 0x5C570 10500 bytes
SHA-256: ce284a281d79ee67dce0356b280f064e330ab98e032d18832d7f96cdc904e5f3
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.
font_07_type1_off0005eef9.bin pdf-font-stream PDF embedded font (type1) at offset 0x5EEF9 16594 bytes
SHA-256: 3fef4d2c8c36588a0e94ac5b595f561bc6ad908cb306215ef84b3bdc59c06681
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
font_09_type1_off000683a3.bin pdf-font-stream PDF embedded font (type1) at offset 0x683A3 15784 bytes
SHA-256: 667a01adc63a599eb7df3d8d991f20a5a5b9ee97ccde4ef4add88c2122dc7332
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.