Malicious PDF — malware analysis report

Static analysis result for SHA-256 9416e720c8ca4c04…

MALICIOUS

PDF

40.2 KB Authoring application: QPDF
MD5: a040cd48c66ae9384e3691370b313afd SHA-1: 0e7ef94854532782244010b0231060d0526490c8 SHA-256: 9416e720c8ca4c04939f75d8553b5b94bf76e94bf630e9163b6feb75f76f3bea
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple embedded URLs that are disguised as content related to 'Eurythmics sweet dreams sheet music'. These URLs point to external PDF files, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly support the malicious nature of this file, classifying it as a phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9976

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://maturefaps.com/uploads/1/3/0/6/130605374/forujewukobepa.pdf
    • http://airporthoppermaynooth.com/uploads/1/3/0/6/130640062/3887633.pdf
    • http://westshoreprojects.com/uploads/1/3/0/5/130547613/vasugabifufe_dezabudujowib_tinagaf.pdf
    • http://minaretsffa.weebly.com/uploads/1/3/0/2/130289543/8401356.pdf
    • http://5pointauto.com/uploads/1/3/0/7/130738765/130738765.html#eurythmics+sweet+dreams+sheet+music

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000101b.bin
e2348175b56d4a3071ae1bb85f245b2170d25de5ca208147ed5a19598ed224b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x101B 9048 bytes
font_01_sfnt_off000053a9.bin
062abeeb0630068c9ebda4cd69880ba7d22c023ef851e82e77d1a768bfa0705b
pdf-font-stream PDF embedded font (sfnt) at offset 0x53A9 17648 bytes