Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba9abf38f653afc8…

MALICIOUS

PDF

44.1 KB Authoring application: PDFedit
MD5: ce9d09280e38fe1ac6394a7896721347 SHA-1: cfc6585b7b82ba35ff0ef19ccd9e083853f4f65c SHA-256: ba9abf38f653afc8fa42eacebed6641b032ebcb695f711cf3d9524e63861d6cd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains multiple embedded URLs pointing to other PDF or HTML files, suggesting a phishing or malware distribution attempt. The presence of these external links indicates a likely attack pattern of luring users to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rollershadeiq.com/uploads/1/3/0/4/130491488/posazefotu.pdf
    • http://tonypandytaxiservices.com/uploads/1/3/0/3/130313037/3682595.pdf
    • http://morby.icu/uploads/2020/01/28/xuxoxamofekewuj.pdf
    • http://hello-baby-toys.com/uploads/1/3/0/5/130543488/130543488.html#d+d+3.+5+ghostwalk

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f9c.bin
8b04f794d2a2ab51faeffc2de957ff19860dc8330d39cc6f1a5cc67f2ee50668
pdf-font-stream PDF embedded font (sfnt) at offset 0xF9C 8176 bytes
font_01_sfnt_off00006525.bin
a88a3252a732d83265545c0d7bca880eac5c53956b7c2c19aa40bc62a0bd5b2d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6525 16492 bytes