Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d57bb73155db3e1…

MALICIOUS

PDF

35.7 KB Authoring application: GIMP
MD5: 8173b71e258772972f7634045b18b262 SHA-1: ffc9f085975b047f3a052ec7c1b832d55d8b7a39 SHA-256: 3d57bb73155db3e1d913b20f8b2dde6bbdbd55e3b360e3e445065b4533fc7779
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The ClamAV heuristic 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the presence of multiple external URLs strongly suggest a phishing campaign. The document body, despite being heavily obfuscated, contains references to 'Animated wallpaper android app' and includes URLs that likely lead to malicious content, indicating a lure to download further malicious files. No scripts were extracted from this sample.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://alloexo.store/uploads/1/3/0/4/130490585/falarakodolekutevat.pdf
    • http://michaelamacpherson.com/uploads/1/3/0/6/130620616/bodukodej.pdf
    • http://bbcsalberta.com/uploads/1/3/0/6/130604723/xirep-zasesemetaz.pdf
    • http://ankezimmermann.ca/uploads/1/3/0/5/130590279/130590279.html#animated+wallpaper+android+app

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f42.bin
22d4d63350e6160c18953739abe24ddf136deb8245c9bc399b5e91793ab12f9c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF42 7076 bytes
font_01_sfnt_off00003c09.bin
dcc3473d1d7fa8f5fe46c82662baca9d61d7413c97481bec6c501631f41b1874
pdf-font-stream PDF embedded font (sfnt) at offset 0x3C09 13164 bytes