Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c1a95ffafd8c109…

MALICIOUS

PDF

33.4 KB Authoring application: Serif PagePlus
MD5: 5229c6d4d3fa07997cd7fb41b70abd5a SHA-1: 8fcf98e5d71808d5ae305f0a9c29f148c7d0abc3 SHA-256: 1c1a95ffafd8c109fb1dfac9a1ea4542b67b963dc5704c0a016e36f50f0ddb07
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is identified as malicious by ClamAV with the signature Pdf.Phishing.TtraffRobotInstall-7605656-0. The document body, though partially corrupted, contains text related to 'Chemical constituents of abelmoschus esculentus' and includes multiple URLs. These URLs are likely used to redirect the user to further malicious content or downloads, a common tactic in phishing campaigns. The presence of multiple external URIs suggests a broad distribution attempt.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://danielreist.org/uploads/1/3/0/6/130620503/1729838.pdf
    • http://marinecitydentist.com/uploads/1/3/0/6/130639325/173567.pdf
    • http://allans-automobiles.co.nz/uploads/1/3/0/6/130604281/fanenolimiv.pdf
    • http://cyclebavaria.com/uploads/1/3/0/3/130313192/xetadu.pdf
    • http://business.berkeleychamber.com/uploads/1/3/0/6/130605307/golupu.pdf
    • http://newarkvalley.org/uploads/1/3/0/5/130546645/130546645.html#chemical+constituents+of+abelmoschus+esculentus

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001084.bin
9ce2a22716688ec6091d0e62986b9eb788e6175f768c3245d24ec54dd8cb52d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1084 8212 bytes