Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfe8ab5f18a7c9a3…

MALICIOUS

PDF

42.3 KB Authoring application: Inkscape
MD5: d0d608a20866685e5a286c1b2f7ef281 SHA-1: 5b8c55912f4d8f98e33821f67f96335754319e7c SHA-256: dfe8ab5f18a7c9a341dfeda40897e7060e588853d7bbde191f3251575c00e343
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as phishing malware. It contains embedded URLs that likely lead to further malicious content, masquerading as free calligraphy worksheets to entice downloads. The document body, though heavily obfuscated, contains references to the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vixofijitobe.weebly.com/uploads/1/3/0/3/130379314/7270951.pdf
    • http://fournildejean.com/uploads/1/3/0/6/130604821/ca71a3.pdf
    • http://xavi.sascharoseescort.com/uploads/2020/01/28/3288763.pdf
    • http://lopolis.net/uploads/1/3/0/6/130621460/744188.pdf
    • http://northwestuu.com/uploads/1/3/0/6/130604517/130604517.html#free+pencil+calligraphy+worksheets+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001052.bin
3d128a1eb9ca846becff48f744e25798378099122300e0e37b37f445118286f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1052 8716 bytes
font_01_sfnt_off00005ecb.bin
b3e61b7d7b8dbcb25e06124f2613e424f2009472c0f20d06ef3485b30c070708
pdf-font-stream PDF embedded font (sfnt) at offset 0x5ECB 16192 bytes