Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9b5a31a60e3c5e7…

MALICIOUS

PDF

27.5 KB Authoring application: PDFedit
MD5: dfd72a86997a8b85f59c1eb5a84f1d2a SHA-1: f000c426d3b2c6940b493c3044198897d7952f52 SHA-256: e9b5a31a60e3c5e703601b8e55bf69eb761d015c915bff927ce2dd8b05438094
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains multiple embedded URLs pointing to other PDF files, suggesting a phishing or malware distribution scheme. The document body, though heavily obfuscated, also contains references to these URLs, reinforcing the attack pattern of luring users to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fastmarketing.icu/uploads/2020/01/28/vefalidopovopiviku.pdf
    • http://mmsestatelettings.com/uploads/1/3/0/2/130272631/4150487.pdf
    • http://paragonhunter.com/uploads/1/3/0/5/130589179/pawesepu-lejupesazixotu-fajav-virodijev.pdf
    • http://msbr.ca/uploads/1/3/0/5/130550777/bapidewugafomusewo.pdf
    • http://sharedtravel.voyagerwebsites.com/uploads/1/3/0/6/130604986/130604986.html#f+t+c+ka+full+form

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001024.bin
0000b568f0b017c5eb6a356faa45095be9c901415595dd6d95e311428378c6d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1024 8208 bytes