Malicious PDF — malware analysis report

Static analysis result for SHA-256 ded67aefacee7f09…

MALICIOUS

PDF

34.5 KB Authoring application: Smallpdf Desktop
MD5: c79bbcb09fe9f8b64e52ec7efd0dee4d SHA-1: ca7fd570212874ac667eea291567a8951b7adf50 SHA-256: ded67aefacee7f094d8eccd95f5de2c13c62c4e54ef8079786b45a699803792b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded URLs, one of which is directly referenced by a heuristic. The document body, though heavily corrupted, contains text that appears to be song lyrics, suggesting a lure to disguise the malicious intent. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection attack. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://rekwiredcosmeticsllc.com/uploads/1/3/0/7/130740297/591e04710.pdf
    • http://studyconnectnz.com/uploads/1/3/0/6/130605493/nalajixeso.pdf
    • http://windfallpartners.net/uploads/1/3/0/6/130621684/novin.pdf
    • http://money4real.org/uploads/1/3/0/5/130547024/pilelawiruninenaxa.pdf
    • http://juliejesternewman.com/uploads/1/3/0/7/130775052/130775052.html#buffalo+soldier+lyrics+song+meanings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001034.bin
01a0a6a9495af8dba218abd701df3f76ad6df1c213ed6f379ebc07c9bf7e99f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1034 8084 bytes