Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9c26bd727390312…

MALICIOUS

PDF

35.5 KB Authoring application: OpenOffice.org
MD5: c1b504a0fbe5501d5ef1c46a2cf45741 SHA-1: f347c931dba2caaab1d2fb0d49b0594069a20b3f SHA-256: f9c26bd7273903121172d59e7e57af0f798f14d6fa722d7bea139d6848f29cdd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is a PDF document that contains multiple embedded URLs pointing to external resources. The ClamAV detection and ML classifier indicate malicious intent, likely related to phishing or malware distribution. The document body, though heavily obfuscated, contains references to software downloads, aligning with the phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ginandtarnish.com/uploads/1/3/0/3/130379696/foxudivizedon.pdf
    • http://ksupayroll.com/uploads/1/3/0/6/130604310/gejabigojovopemuxa.pdf
    • http://zegugo.myaccount-solution.net/uploads/2020/01/28/5928980.pdf
    • http://easternfclass.ca/uploads/1/3/0/4/130475964/naniwiwexikaxuj.pdf
    • http://reikisoundbliss.com/uploads/1/3/0/2/130273962/130273962.html#boson+netsim+11+free+download+with+crack

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000121d.bin
c33f0e18ffcc8562dd9255c88d007af0f22374fe89ff7fcc7f1fe902b29fab11
pdf-font-stream PDF embedded font (sfnt) at offset 0x121D 8620 bytes