Malicious PDF — malware analysis report

Static analysis result for SHA-256 eaef7bddbaadb9c6…

MALICIOUS

PDF

40.7 KB Authoring application: OpenOffice Draw
MD5: e79a7bf01da0095492907ecd95066836 SHA-1: 5b83e1489500df6cdf65dead444cb04c15a3a23a SHA-256: eaef7bddbaadb9c6c39621cb4700f1a48cc186c2297766e5d6f68b9079528b98
94 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains multiple embedded URLs that likely lead to further malicious content or downloads. The document body is heavily obfuscated and contains what appear to be URL strings, reinforcing the phishing or malware delivery vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://drvdv.com/uploads/1/3/0/3/130379287/jigesanebuk_popukokatogik_fitesapazemide_moxamibegipet.pdf
    • http://besthueproducts.com/uploads/1/3/0/6/130605012/modilozeroxemevokab.pdf
    • http://myneverendingbucketlist.com/uploads/1/3/0/4/130488891/4126917.pdf
    • http://tophatalgarve.com/uploads/1/3/0/4/130436172/350a00688fab5.pdf
    • http://nicoleedwardslimited.net/uploads/1/3/0/2/130289722/74154e.pdf
    • http://mynaturalhairspa.com/uploads/1/3/0/2/130288757/130288757.html#tp-link+tl-wa801nd+n300+wireless+access+point%2Frepeater

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000012fd.bin
16b20e6023baa2ba49417725ef6961f21f18acc00e19571e815c6f7cf3b223bc
pdf-font-stream PDF embedded font (sfnt) at offset 0x12FD 8896 bytes
font_01_sfnt_off0000609f.bin
eaa4dde51fd04d4db8dc223d97e5e1aeb2070941b7c144db1acc557f645d9ab7
pdf-font-stream PDF embedded font (sfnt) at offset 0x609F 4184 bytes