Malicious PDF — malware analysis report

Static analysis result for SHA-256 3712cbba57274529…

MALICIOUS

PDF

48.0 KB Authoring application: Soda PDF
MD5: 6c5fce72d0f4ca923b5e2d1182d8a9c1 SHA-1: a077a5baebf78b288fed478caa75ef0e608bdd5c SHA-256: 3712cbba572745294e2113c9fba066319e45645d2eeeb6994f67f5ad57adab85
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The ClamAV heuristic 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly suggests a phishing campaign. The embedded URLs, particularly the one pointing to 'samrichardson.org', are likely intended to deliver the actual malicious payload. The document body, though heavily obfuscated, contains references to URLs and technical terms, further supporting a phishing or social engineering lure.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://samrichardson.org/uploads/1/3/0/5/130539235/wumusuxeverakut-borajula-sunuxufewemixo-gewokamibago.pdf
    • http://rose-from-concrete.com/uploads/1/3/0/5/130538836/cbae494c6a7cb28.pdf
    • http://miriamswritingportfolio.weebly.com/uploads/1/3/0/5/130588595/3efb96d8cd9.pdf
    • http://davidmarquesibanez.com/uploads/1/3/0/5/130588527/130588527.html#p0344+camshaft+position+sensor+performance

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001061.bin
bd48648e55a3bc15d2759bad79745e1abc300070c624a23848805a6997d39c6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1061 8472 bytes
font_01_sfnt_off000070bf.bin
062abeeb0630068c9ebda4cd69880ba7d22c023ef851e82e77d1a768bfa0705b
pdf-font-stream PDF embedded font (sfnt) at offset 0x70BF 17648 bytes