Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0f0510b3f0ce81c…

MALICIOUS

PDF

39.5 KB Authoring application: Inkscape First seen: 2020-09-24
MD5: 033d78c971afe47658dcc045d6e302c5 SHA-1: 78582cacd63ef8cba36c32952fb1a9825ebcd37c SHA-256: d0f0510b3f0ce81cefe4d8e187365325f56e992a8762a76f57d719855c41c2d6
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the presence of multiple unknown reputation URLs strongly indicate malicious intent. The document body, despite being heavily obfuscated, contains references to URLs that likely serve as download locations for further malicious content. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://theapothecaryagency.org/uploads/1/3/0/7/130739419/jelonitew.pdf PDF link annotation
    • http://caseyhd.com/uploads/1/3/0/4/130489386/gakekajavijubakul.pdfIn PDF document text
    • http://parker4judge.com/uploads/1/3/0/7/130739502/7836b2eb296ad.pdfIn PDF document text
    • http://moodlabnewlife.nl/uploads/1/3/0/2/130289809/130289809.html#bug+cat+capoo+stickers+whatsapp+apkIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000fe1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFE1 8616 bytes
SHA-256: cbb59510555efa9edb23b8b679c61c83ae79a09581b39ec5d176e82177f66bff
font_01_sfnt_off00004a53.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4A53 16208 bytes
SHA-256: b4eaba1313c2ae02e0840532e8df49817f4492e706e7fc7006fa435ca033da2a
font_02_sfnt_off00005f2e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5F2E 2668 bytes
SHA-256: bb66d78edca8aa75a8db461931e44ad6eab12e4cd439df836d92d13c6ef6c22d