Malicious PDF — malware analysis report

Static analysis result for SHA-256 e54081ab91c5bce3…

MALICIOUS

PDF

49.6 KB Authoring application: OpenOffice Draw
MD5: bcc646d1b25d924ba0e4360b550b97d4 SHA-1: b49fbcdfb32e10cf6b333783ef1c67b0dfed2eb5 SHA-256: e54081ab91c5bce3ec809ecd8199eef1452b4d7e14df390f765ea5324f9d0381
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is a PDF that contains an embedded URI pointing to another PDF. The ClamAV detection and ML classifier strongly indicate maliciousness, likely related to phishing. The document body text is heavily obfuscated and does not provide clear intent, but the presence of external URIs suggests a delivery mechanism for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://tomobotefagat.weebly.com/uploads/1/3/0/5/130539155/d94c35ffba869bc.pdf
    • http://lightisadrug.com/uploads/1/3/0/5/130588583/wegotu.pdf
    • http://peni.tandr.ru/uploads/2020/01/29/553180d29a7f22.pdf
    • http://ankezimmermann.ca/uploads/1/3/0/4/130489467/130489467.html#william+borlase%27+s+sixth+form+open+evening

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000100d.bin
4c0000fe1eb26ccdb7a8c97b9a96d58057c0fc3cccc9aa65ddbb50329e878ad1
pdf-font-stream PDF embedded font (sfnt) at offset 0x100D 8544 bytes
font_01_sfnt_off00007392.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x7392 16036 bytes
font_02_sfnt_off000087b7.bin
2c32c498f23db3cae400dac070c72b38d41a5d5dbe5041cbe08e7cee44e1acfd
pdf-font-stream PDF embedded font (sfnt) at offset 0x87B7 2648 bytes