Malicious PDF — malware analysis report

Static analysis result for SHA-256 2db3712d98698363…

MALICIOUS

PDF

43.0 KB Authoring application: PDF Studio
MD5: 56a7fd44e97f4b21c8923cfb587e6a77 SHA-1: a21a688fd1162204b0bf3ed8669c3b0ec2300cab SHA-256: 2db3712d98698363f1f184add172cbb540dcea7160ec676f91a0633dde559dcd
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The ClamAV heuristic identified this PDF as 'Pdf.Phishing.TtraffRobotInstall-7605656-0', indicating a phishing attempt. The embedded and external URLs point to suspicious PDF files, suggesting the document's purpose is to trick the user into downloading further malicious content. The document body contains text related to grammar, which is likely a lure to disguise the malicious intent.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://napolke24.online/uploads/2020/01/28/8649593.pdf
    • http://center64.com/uploads/1/3/0/4/130477007/9257447.pdf
    • http://cookseyplumbing.com/uploads/1/3/0/2/130288456/d990295ac3442ed.pdf
    • http://ktburke.com/uploads/1/3/0/4/130435846/dapijarozixujij.pdf
    • http://thehappygirlstore.com/uploads/1/3/0/5/130540182/130540182.html#combine+two+sentences+using+relative+pronouns

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000102b.bin
4806b0c4ac80fdda7c826d381da7593c088e30afb3222dad0c773101b1391372
pdf-font-stream PDF embedded font (sfnt) at offset 0x102B 8264 bytes
font_01_sfnt_off00006101.bin
1719be247db8a5ec88333ea8807862d8cb1efcd09b83c5bbdb6278da05fc00b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x6101 16364 bytes