Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2ccd413aca55082…

MALICIOUS

PDF

47.7 KB Authoring application: Karbon
MD5: b4b8db0e026940af18d3059d2f337304 SHA-1: 17bae533b25f65ecb05dc36de32f95a8380abd12 SHA-256: a2ccd413aca550820f048d5c1c8e59d4b4ecc1a9a591e28efabad2b98afc0a21
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document that contains embedded URLs, one of which is flagged as malicious by ClamAV. The document body text, though partially truncated and obfuscated, mentions "Nocturnal seizures icd 10" and appears to be a lure to encourage the download of further malicious content. The presence of multiple suspicious URLs further supports the phishing and malware delivery intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cookieclickerfree.weebly.com/uploads/1/3/0/4/130477234/getuso.pdf
    • http://brownsugarbabyllc.com/uploads/1/3/0/4/130488661/3456628.pdf
    • http://spectaclesbroadway.com/uploads/1/3/0/6/130604724/maxuxodef.pdf
    • http://maephimbeaches.com/uploads/1/3/0/7/130739046/5836544.pdf
    • http://rehphotography.org/uploads/1/3/0/5/130588551/130588551.html#nocturnal+seizures+icd+10

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f66.bin
79e1b5a33b3ac588382e17ccbf00aee81f76e3ddf0767fac96f1aaa824213d74
pdf-font-stream PDF embedded font (sfnt) at offset 0xF66 8536 bytes