Malicious PDF — malware analysis report

Static analysis result for SHA-256 a97f7523251e7cfb…

MALICIOUS

PDF

29.0 KB Authoring application: Soda PDF
MD5: a92bfbc470627823e3c014f638566401 SHA-1: 21a7daa0be4d1074904663494245de5a5ae86fc6 SHA-256: a97f7523251e7cfbe2f67d478c6b6e4a7afeba22a4115964f7fe4772365ddfc9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document identified as malicious by ML classifiers and ClamAV, specifically as Pdf.Phishing.TtraffRobotInstall. It contains multiple embedded URLs that likely serve as lures for users to download further malicious content. The document body mentions 'Layers of fear inheritance trophy guide', suggesting a social engineering pretext to entice users to click on the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kadibudorotira.weebly.com/uploads/1/3/0/4/130477613/kasuwomid-nejebil-palisuwularan.pdf
    • http://pkosinski.com/uploads/1/3/0/6/130605269/17f93054d7be.pdf
    • http://zagukur.nissancentr.com/uploads/2020/01/28/darupafitapama_fefik_jowom_sitikijutadusox.pdf
    • http://lulufita.dcdinspecciones.com/uploads/2020/01/27/845070.pdf
    • http://heatherscustomcookies.com/uploads/1/3/0/6/130621544/6837b526ceed.pdf
    • http://misbailes.com/uploads/1/3/0/6/130622058/130622058.html#layers+of+fear+inheritance+trophy+guide

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000114c.bin
920128d077a43d2701949763b366f53da889a98d5c9bd19fff36c4cb35ce8b52
pdf-font-stream PDF embedded font (sfnt) at offset 0x114C 9252 bytes