Malicious PDF — malware analysis report

Static analysis result for SHA-256 e627fc880496f6a2…

MALICIOUS

PDF

40.8 KB Authoring application: Smallpdf Desktop
MD5: f79b3ed94cf3ec00a1964dc30493788c SHA-1: cd2e93d3459d2738a5f68d0d4664bb359023b7c0 SHA-256: e627fc880496f6a263f13f551e2c8c465fe467fb6672bcd12bca29f617536e69
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains multiple embedded URLs that likely serve as lures for phishing or malware distribution. The document body, though partially corrupted, suggests a pretext of providing educational material ('Grade 7 linear equations worksheets pdf') to trick users into interacting with the malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://camdenlawncare.com/uploads/1/3/0/5/130543353/mivoj_ledirerutomugam_wuduvusafon_libubexezaweseg.pdf
    • http://avadhaniestate.net/uploads/1/3/0/3/130323302/5216272.pdf
    • http://costaparadiso.holiday/uploads/1/3/0/6/130604516/1868990.pdf
    • http://djournalebydn.com/uploads/1/3/0/6/130620745/8768503.pdf
    • http://jumagi.kazahstan-kepy.fun/uploads/2020/01/28/53007ba.pdf
    • http://multistreams.com/uploads/1/3/0/6/130621934/130621934.html#grade+7+linear+equations+worksheets+pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001090.bin
a52a8618de0d6221a3623662b6c30724a37596f1f7197733a55ec491623573c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1090 7900 bytes
font_01_sfnt_off000058dd.bin
f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d
pdf-font-stream PDF embedded font (sfnt) at offset 0x58DD 16204 bytes