Malicious PDF — malware analysis report

Static analysis result for SHA-256 785b32e78888afeb…

MALICIOUS

PDF

39.4 KB Authoring application: OpenOffice.org
MD5: f2eb575794174e905975802f72a73497 SHA-1: 34abdf1f35f3b8ebceea8995022497a6d9a5b3e7 SHA-256: 785b32e78888afeb5a9d8930810de144b87a554b798a95fc7e08250f964deea0
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by multiple engines, including ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The document body contains embedded URLs that likely lead to the download of further malicious content, such as another PDF. The presence of external URIs and embedded URLs strongly suggests a phishing or social engineering attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://tuv.kuhnimsc02.icu/uploads/2020/01/28/48afc9cd.pdf
    • http://britemoonmarketing.com/uploads/1/3/0/6/130620614/lagizisavovit_mazetagogedexo_pisesuga_nabudufipofe.pdf
    • http://skinnytiffy.com/uploads/1/3/0/5/130588205/807419.pdf
    • http://daviddcal.com/uploads/1/3/0/7/130739560/xebujopekawaxo_nevijawopasoz.pdf
    • http://oakleighfarmstud.com/uploads/1/3/0/3/130379101/a12a6b13f.pdf
    • http://rochecenter.org/uploads/1/3/0/5/130539344/130539344.html#esc+guidelines+acute+pulmonary+embolism+2014

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000111f.bin
21957e9a9aa0e48edb4807d59435e8a53013d22dde32e017135f0fdaaac4d926
pdf-font-stream PDF embedded font (sfnt) at offset 0x111F 8200 bytes