Malicious PDF — malware analysis report

Static analysis result for SHA-256 b633eadebd9231f8…

MALICIOUS

PDF

44.5 KB Authoring application: PDF Studio
MD5: a692182054df364fa52dc1f6909330b5 SHA-1: d62737b684b3d1588d4bf0e5559d701edfe5089c SHA-256: b633eadebd9231f8bff06bedc2561d186d25a26052b7aa76e6f48df2e3e40605
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is a PDF document that contains embedded URLs pointing to other PDF files. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent, likely phishing or malware distribution. The document body, while containing educational material titles, also includes these malicious URLs, suggesting a lure to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dog.rutv.fun/uploads/2020/01/29/5214308.pdf
    • http://promiseskepthomecare.com/uploads/1/3/0/3/130323141/2171396.pdf
    • http://solfeggiohypnosis.com/uploads/1/3/0/3/130313333/fuditose.pdf
    • http://sarahpoulgrain.com/uploads/1/3/0/3/130323174/130323174.html#fisica+2+bachillerato+anaya+pdf

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000101d.bin
effaa76396ced4d0d943df2e3f065296f2a2a4c0bc09a2c53047fdf80dfb0fa3
pdf-font-stream PDF embedded font (sfnt) at offset 0x101D 9480 bytes
font_01_sfnt_off000058c6.bin
6db2f878e0fd57d3a351d0d81a5ccd7b58f68df6728dadc3aee3ebeb1a1d6e60
pdf-font-stream PDF embedded font (sfnt) at offset 0x58C6 16068 bytes
font_02_sfnt_off00006cd0.bin
1957428794578a072b8983e864e5701b52391162abfb2d6d14c6295fa8a16687
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CD0 6444 bytes