Malicious PDF — malware analysis report

Static analysis result for SHA-256 80cd0bd72f8b81ed…

MALICIOUS

PDF

48.9 KB Authoring application: Adobe PDF Library 9.0
MD5: 16fb1e0895a004b254c6d2f2e18a120c SHA-1: fc0a401ebe43d26580a4d19faa37e2d7a8992e08 SHA-256: 80cd0bd72f8b81ed678800d73cd3600314956f8f781ca9565c5c55ba16a26038
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing-related PDF. It contains multiple embedded URLs pointing to other PDF files, suggesting a lure to download further malicious content. The presence of these external links indicates an attempt to direct users to potentially harmful resources, aligning with phishing or malware distribution tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://msgaccounting.com/uploads/1/3/0/2/130271083/4c34a30dbae66f.pdf
    • http://tattoosbyjessvann.com/uploads/1/3/0/6/130621324/xazogofiwu-dupokapib-fodusakupewol.pdf
    • http://alessertraveledroad.com/uploads/1/3/0/5/130541208/9781ad4a.pdf
    • http://mjmallc.com/uploads/1/3/0/2/130270832/sipuluwemik.pdf
    • http://tel.lechenienarkomanii-blagoveshhensk.ru/uploads/2020/01/29/derif-givopasudude-zoxowanu-wolaxakan.pdf
    • http://misssoutheastpageantry.us/uploads/1/3/0/4/130488357/130488357.html#mechanism+of+antiseizure+drugs
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001131.bin
3ded71e01be8f084b7fd56f0de370e9c6cd897d2ad9d2fa594290a85814ceac8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1131 8644 bytes
font_01_sfnt_off000079f2.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x79F2 16036 bytes