Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef8ab468bf6f5c3c…

MALICIOUS

PDF

36.5 KB Authoring application: GIMP
MD5: 2c863b3ad73cf467ea86dd2cc8923596 SHA-1: 49aeaf067a9d803104c558d2b767bab3dbe6c7e4 SHA-256: ef8ab468bf6f5c3cf61f5dc734e998531ac5253411c9c973f7874bcd52c64a4f
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is a PDF document that contains embedded URLs pointing to other PDF files. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly suggests a phishing or malicious redirection campaign. The ML classifier also flagged the PDF as malicious. The document body contains garbled text but includes URLs that are likely part of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://povinagu.weebly.com/uploads/1/3/0/5/130588430/09ce0c3d61a2160.pdf
    • http://radioholland.co.za/uploads/1/3/0/7/130739640/8307.pdf
    • http://thestickermill.com/uploads/1/3/0/6/130605492/kanexajiwaf.pdf
    • http://bigexak.geltser.info/uploads/2020/01/27/237d67fe6f.pdf
    • http://adentaperu.com/uploads/1/3/0/6/130603749/7601856.pdf
    • http://binarytradeassistant.club/uploads/1/3/0/6/130620453/130620453.html#critical+path+in+software+project+management

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000121b.bin
28ab98f1a1e57225e218dedcbc63c8aa32cf843aad514d9d2d4d8fd4ff6f6cc9
pdf-font-stream PDF embedded font (sfnt) at offset 0x121B 7868 bytes
font_01_sfnt_off00005367.bin
3d52fc27d04b8b84b219df719738f768697e09c2050136bc1fe69fcddf4eca6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x5367 2652 bytes