Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a99c3140f5dc667…

MALICIOUS

PDF

29.4 KB Authoring application: Soda PDF
MD5: 1b5b9e4d2330ad3d14d03fde76fe4ae3 SHA-1: 823c8a83fff482a5dc88c8ad4c1202f893a5b333 SHA-256: 9a99c3140f5dc667bce2562490fc2bd7387107836f4cb9ca07d79d4282879715
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file is identified as malicious by ClamAV and an ML classifier, and contains multiple external URIs pointing to other PDF files. The document body, despite being heavily obfuscated, suggests a lure related to a 'worksheet laboratory equipment' to entice users to click on the embedded malicious links. The primary malicious links are http://dgias.pl/uploads/1/3/0/4/130483277/wupivavuzenek.pdf and http://mikeajames.com/uploads/1/3/0/6/130640052/a974a3848eb899f.pdf.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dgias.pl/uploads/1/3/0/4/130483277/wupivavuzenek.pdf
    • http://mikeajames.com/uploads/1/3/0/6/130640052/a974a3848eb899f.pdf
    • https://duzixikepur.weebly.com/uploads/1/3/0/2/130270834/vabijez.pdf
    • http://kineffect.com/uploads/1/3/0/5/130545485/jojumawi.pdf
    • http://mikeintucson.com/uploads/1/3/0/6/130621025/130621025.html#worksheet+laboratory+equipment

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000101b.bin
f3d766c7d748e1bd92a9634cd72bca9811d91789cd56828879f0a7889160c961
pdf-font-stream PDF embedded font (sfnt) at offset 0x101B 8536 bytes