Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6b4ca5f0ef4fb2c…

MALICIOUS

PDF

33.3 KB Authoring application: Adobe PDF Library 9.0
MD5: 02504153ae4c58a81e755c3900690ae9 SHA-1: 218c8f226873751e95aa02ff308d026213d81e94 SHA-256: f6b4ca5f0ef4fb2c93817d4019073a08d7d74e21ba28e8a9ecfd1f4eff2b08b9
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document identified as malicious by ML classifiers and ClamAV. It contains multiple embedded URLs that likely lead to further malicious content or phishing pages. The document body, while containing educational-sounding text, also includes these URLs, suggesting a lure to download additional malicious files or visit phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://our0genealogy.org/uploads/1/3/0/5/130550966/1184e312d2037.pdf
    • http://mnsbearings.com/uploads/1/3/0/5/130550914/fekif.pdf
    • http://theartofshade.de/uploads/1/3/0/4/130476786/pakexemubaros.pdf
    • http://officialbrookekelly.com/uploads/1/3/0/4/130483389/8191008.pdf
    • http://theprotocolandetiquetteschool.com/uploads/1/3/0/4/130435574/130435574.html#maths+tables+from+1+to+20+worksheets
    • http://theprotocolandetiquetteschool

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000ffd.bin
b9c3c3656c1016212969a6b34043cf0714a417441df59a54dc4c7c4f1b0453a5
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFD 7668 bytes