Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb92a0d228215886…

MALICIOUS

PDF

56.1 KB Authoring application: PDFBox
MD5: 2a76ad6c5f6db47881f943e93afd7e5d SHA-1: 13f72909138fd37ae77bff61a143af8579fb77a3 SHA-256: eb92a0d228215886155d5c110d7b894f054484d0d39141c461edb1ffa083107d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The ClamAV detection and ML classifier strongly indicate malicious intent. The PDF contains multiple embedded URLs, one of which is also flagged by a PDF_URI heuristic. These URLs likely lead to further malicious content or phishing pages. The document body text appears to be corrupted or obfuscated, making it difficult to determine the exact lure, but the presence of URLs points to a download or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://thepaleocaveman.com/uploads/1/3/0/6/130604441/relolesigofadaxusa.pdf
    • http://jacquegraham.net/uploads/1/3/0/7/130739619/befolugepabifif_kosoweja_banifum.pdf
    • http://sadetemab.zavod-tseh.ru/uploads/2020/01/28/5256019.pdf
    • http://nahsesouthflorida.org/uploads/1/3/0/6/130639467/lelemawed.pdf
    • http://ssbcmarketing.com/uploads/1/3/0/6/130604807/juneparetesama_poramut.pdf
    • http://northeastwaterdamage.net/uploads/1/3/0/6/130604241/130604241.html#royal+scots+dragoon+guards+bagpipe+sheet+music

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011d4.bin
71af2246ce3d7b764ad89de873a8c1c6c5b465f70dd1d7f227451b56e65d8eea
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D4 9052 bytes