Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5285bde84ac58df…

MALICIOUS

PDF

33.9 KB Authoring application: Inkscape
MD5: 0a821e62d1d2becc1c723ae1bca99e29 SHA-1: 900648eb4badab1325fa5807829c550087c0235a SHA-256: e5285bde84ac58dfaa61cffa06fd893322ee2c9d3f36a74cd92e18a29ddfccbe
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document that masquerades as a high heel shoe template to trick users into downloading it. The document contains multiple external URLs, one of which is also listed as an embedded URI, pointing to other PDF files. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://metaprotection.com/uploads/1/3/0/2/130288412/relilezugideremegade.pdf
    • http://codynaz.com/uploads/1/3/0/5/130589274/8436819.pdf
    • http://nobookingfee.org/uploads/1/3/0/4/130489072/a3c4e6c.pdf
    • http://nevrapoint.com/uploads/1/3/0/5/130588784/a6acd01d92a3e.pdf
    • http://zuwatibu.lifetime24.ru/uploads/2020/01/29/4de88a1b81b.pdf
    • http://riversidecountyhistory.org/uploads/1/3/0/3/130323381/130323381.html#high+heel+shoe+template+printable

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001069.bin
1885434b445b3d0f99e96029093e56a351a9e03c2c1aabb00710ff4213de6f6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1069 8472 bytes