Malicious PDF — malware analysis report

Static analysis result for SHA-256 b019c8c44f959704…

MALICIOUS

PDF

46.2 KB Authoring application: Adobe PDF Library 9.0 First seen: 2020-09-24
MD5: 577bd45f00a8ee75fcae3d6632cc5bad SHA-1: cb6b6cb5b350d29a528adb499bd6c50822b905a4 SHA-256: b019c8c44f9597043b13fff7b3b9ba8f2d9f188ea127728bb0cab2456cb14bbb
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is a PDF document identified by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0. It contains multiple embedded URLs pointing to external PDF and HTML files, suggesting a phishing or malware distribution attempt. The presence of a download button heuristic further supports the lure-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://edukasi.info/uploads/1/3/0/6/130604529/fee3ba6.pdf In PDF document text
    • http://flourishhealthmd.com/uploads/1/3/0/4/130489128/daxepen-dudedet-melukorilodu-dutaji.pdfIn PDF document text
    • http://ourchildrensfund.com/uploads/1/3/0/5/130540065/6947717.pdfIn PDF document text
    • http://neokundalini.org/uploads/1/3/0/3/130324137/130324137.html#job+interview+tell+me+about+yourself+answersIn PDF document text
    • http://kalaman.net/uploads/1/3/0/3/130323602/5264955.pdfPDF link annotation

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000106c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x106C 8568 bytes
SHA-256: e63c639e96d08c4e6dc137d444e8671b9190b60b8c392e629f22bbcf992cf83c
font_01_sfnt_off00007b5e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7B5E 1708 bytes
SHA-256: 83459e82cebe561b9e65dda6a09953c9e35f75e5df0fa62a624e1833cc5b8086