Malicious PDF — malware analysis report

Static analysis result for SHA-256 f082d8c40ee9ef77…

MALICIOUS

PDF

37.7 KB Authoring application: pstoedit
MD5: d4f15e90d64328629a27596a4b20338e SHA-1: 41fa67514d55a4312d164fded9088c730ab52d97 SHA-256: f082d8c40ee9ef77a3c7d9cd24c4de7b5921d67445d2bd7a9edc24cb6815a587
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is a PDF containing embedded URLs that lead to other PDF files or an HTML page, disguised as a 'solutions manual'. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier strongly indicate malicious intent, likely phishing or malware distribution. The document body, though heavily corrupted, contains fragments of the lure text and the malicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ebc3.org/uploads/1/3/0/6/130604447/8686932.pdf
    • http://latoniaprice.com/uploads/1/3/0/4/130435978/nadamuxawiw_sipegoxum_zagetipov.pdf
    • http://ngpsychology.com/uploads/1/3/0/4/130436272/biritibagewav.pdf
    • http://mhrandlenovels.com/uploads/1/3/0/4/130489297/130489297.html#engineering+mechanics+statics+13th+edition+hibbeler+solutions+manual

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000045f7.bin
3792ea9cb7a638d95f6369ff25055bd88da1cb0dd38bb382c7511605befd11da
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x45F7 18164 bytes
font_00_sfnt_off0000101b.bin
188c0c566811d274aa0a50e9137159413ec9d25e13a83668a88e2c115fb67b49
pdf-font-stream PDF embedded font (sfnt) at offset 0x101B 8252 bytes