Malicious PDF — malware analysis report

Static analysis result for SHA-256 ffff4596a754a111…

MALICIOUS

PDF

42.0 KB Authoring application: pdf-parser
MD5: 27aa2b8ca58f4703adb97abe045157f5 SHA-1: a785a2d7f4a2e5a9550448d90ec8e8be3bd7e772 SHA-256: ffff4596a754a11165955383d56a534259a5e9cc7137ed6feb67b5046ef05776
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF containing embedded URLs that point to other PDF files, suggesting a multi-stage download or redirection mechanism. The document body references 'Pokemon sun and moon game mod apk', indicating a lure to entice users to click on the malicious links. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malware distribution intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://afaparents.org/uploads/1/3/0/6/130604110/kaxetuda.pdf
    • http://amredco.com/uploads/1/3/0/5/130589389/b2cd35286e1.pdf
    • http://orthogistic.com/uploads/1/3/0/6/130621429/4713573.pdf
    • http://staceyphillips.online/uploads/1/3/0/5/130550931/pisusub.pdf
    • http://newperspectivemedical.com/uploads/1/3/0/7/130738962/130738962.html#pokemon+sun+and+moon+game+mod+apk

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001005.bin
24f9ea3a6bee440d555634ac606946c3f26832db3619ea6835d65c63230001b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1005 8740 bytes
font_01_sfnt_off00005e03.bin
b32191d6dac1903e3ec139b3e91a40f13938de3dcb588c278e0c60d9389fdf24
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E03 16096 bytes