Malicious PDF — malware analysis report

Static analysis result for SHA-256 78a080c262af9006…

MALICIOUS

PDF

30.7 KB Authoring application: Scribus
MD5: e48fda42fbc88b90c5fc88ed8a186c2b SHA-1: 91b0e00139478923891c7d91baa560b8a5c0c4e9 SHA-256: 78a080c262af90061e7f2bee1f9c883a0b83481182b8afe93d4cf84b0840a29d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is a PDF that contains embedded URLs, one of which is flagged as malicious by heuristics. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body, though garbled, contains text related to 'good night images', likely a lure to disguise the malicious nature of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lovelotegag.weebly.com/uploads/1/3/0/6/130603958/xumisozefa_tedov_pavifosesukowa.pdf
    • http://koffienator.nl/uploads/1/3/0/2/130287299/505d69.pdf
    • http://raz-ezzhaya.ru/uploads/2020/01/28/bonoliz.pdf
    • http://nursesnowinc.org/uploads/1/3/0/4/130489448/wifumenetomola_lebeladutov.pdf
    • https://fobujupedexep.weebly.com/uploads/1/3/0/5/130545932/linikoga.pdf
    • http://nationalriskmanagementgroup.com/uploads/1/3/0/2/130270845/130270845.html#good+night+images++for+whatsapp+tamil

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000108a.bin
6eed0393c02380421013559be4a8be327c5c7fb3da709addae961ba9f8bcbbc9
pdf-font-stream PDF embedded font (sfnt) at offset 0x108A 7736 bytes