Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebb0c65d0430ff29…

MALICIOUS

PDF

34.3 KB Authoring application: Pdftk
MD5: f0cb880f2f29287c3e84bddb315fb853 SHA-1: 69e19bab7ff742511b7edf6b2c39944ffba61031 SHA-256: ebb0c65d0430ff2965c7da4e44e5f30b29da1b11e7b989e9bff6f80644cf2c26
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document identified as malicious by multiple detection engines, including ClamAV and an ML classifier. The document body contains multiple embedded URLs that point to other PDF files, suggesting a phishing or social engineering lure. The presence of PDF_URI and EMBEDDED_URL heuristics further supports this attack pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://groupbrew.com/uploads/1/3/0/6/130604151/vilonitilam-neleviped-mifaje.pdf
    • http://libertygraphicsok.com/uploads/1/3/0/6/130621501/gibopagote.pdf
    • http://sweetstaysalem.com/uploads/1/3/0/2/130291589/1142c526287c6.pdf
    • http://pupafuw.hallo-mensen.com/uploads/2020/01/28/nesebadanipov.pdf
    • http://guiadoipva.com/uploads/1/3/0/7/130740251/motomuwuvul.pdf
    • http://cyclebavaria.com/uploads/1/3/0/3/130323175/130323175.html#intake+and+output+sheet+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010bf.bin
2cf78b25c9410059c1901ad0a9c5fee9b9f4a5a2a3db2abcf07289d51b696f31
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BF 8732 bytes