Malicious PDF — malware analysis report

Static analysis result for SHA-256 e297c591a17d3931…

MALICIOUS

PDF

38.5 KB Authoring application: Smallpdf Desktop
MD5: ea137b472880f18f01cce88e02babff5 SHA-1: 8f6ea77f2fb389903e0be7aea2ff11707fc41d58 SHA-256: e297c591a17d3931061b40c5b85f9f52dbcee29b241cafb046e391eaa9732819
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file was detected by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0, indicating a phishing or malware distribution attempt. The document body contains embedded URLs that likely serve as lures to download further malicious content. The presence of multiple Weebly and other suspicious domains suggests a campaign distributing malicious PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jokuvidisuw.weebly.com/uploads/1/3/0/3/130323642/619c18e4a6705d.pdf
    • https://roworuwofizema.weebly.com/uploads/1/3/0/5/130546645/81756399e7b66d0.pdf
    • http://themountainforge.com/uploads/1/3/0/4/130435851/6036917.pdf
    • http://pifif.knives.promo/uploads/2020/01/29/sobokajim.pdf
    • http://ruditanije.pokupka-perfecto.ru/uploads/2020/01/29/roborosoka-bomijaxe-gatujeruxidulo-gunelutitolima.pdf
    • http://cfthomas.com/uploads/1/3/0/4/130476485/130476485.html#holman+manual+water+timer

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000109c.bin
a1327a5fc651883664a22bd7303457869717a1bb984ea54942b22ef4f1066253
pdf-font-stream PDF embedded font (sfnt) at offset 0x109C 7892 bytes
font_01_sfnt_off00004efd.bin
ef2dff89daf5b51a8f899599357862a5c8f3f00d67ae8205a09308246fbbbe4b
pdf-font-stream PDF embedded font (sfnt) at offset 0x4EFD 16312 bytes