Malicious PDF — malware analysis report

Static analysis result for SHA-256 fba532804cfcdbc5…

MALICIOUS

PDF

32.0 KB Authoring application: Serif PagePlus
MD5: adaf09d561f6ca9ea2451e47110d394d SHA-1: 0cf42f1e31798a7ddcd641879ddb8e9af15809f7 SHA-256: fba532804cfcdbc5e2c3f9954e84202d841e82cd214d0ac7ff278f27c4f8c406
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document that contains embedded URLs. One of these URLs, http://dancemarketing.co/uploads/1/3/0/4/130478470/7865697.pdf, is flagged as malicious by heuristics and ClamAV. The document body, though partially corrupted, suggests a lure related to 'Jysk furniture bed sheets' and 'HYGGE DAYS' with a 'SHOP NOW' call to action, indicating a phishing or scam attempt to entice users to download the linked malicious PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://dancemarketing.co/uploads/1/3/0/4/130478470/7865697.pdf
    • https://xopilavuxuneki.weebly.com/uploads/1/3/0/6/130604737/ef0020141.pdf
    • https://nalizoxuvot.weebly.com/uploads/1/3/0/4/130489228/kirodonew.pdf
    • http://nicolewilliamswrites.com/uploads/1/3/0/5/130544118/7872102.pdf
    • http://xaxamataku.katalog-z.com/uploads/2020/01/27/9151234.pdf
    • http://sharedtravel.voyagerwebsites.com/uploads/1/3/0/6/130621143/130621143.html#jysk+furniture+bed+sheets

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001092.bin
bcac976d74052624e638264cff58477d1369c9e69ce0cdf4590a946aeb2fdadf
pdf-font-stream PDF embedded font (sfnt) at offset 0x1092 8804 bytes