Malicious PDF — malware analysis report

Static analysis result for SHA-256 51e77049820db9ff…

MALICIOUS

PDF

40.7 KB Authoring application: SWFTools
MD5: 3d2af159512dff43317812caf49fc583 SHA-1: 11d948f025bac3e63427b2ed08b118b6a4a87253 SHA-256: 51e77049820db9ffcc11d9b6442ccaa56582ff4f4dbc4dba0199443b7d5ab71d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file was detected by ClamAV as Pdf.Phishing.TtraffRobotInstall-7605656-0, indicating a phishing or malicious intent. The document body, though heavily obfuscated, contains references to URLs that likely serve as download locations for further malicious content. The presence of multiple embedded URLs reinforces the likelihood of a phishing or malware distribution campaign.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://uclabbsa.weebly.com/uploads/1/3/0/2/130289558/906947cd5a697a1.pdf
    • http://nancebmecleaning.com/uploads/1/3/0/6/130639329/4967824.pdf
    • https://desutunidiruse.weebly.com/uploads/1/3/0/3/130313046/67abe.pdf
    • http://theelfbox.com/uploads/1/3/0/4/130435712/130435712.html#jumbled+sentences+for+class+3+with+answers

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000fd0.bin
254055e0089fce676b6d548c154d172f9bcbbf79593047b69f7adc2532c44962
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD0 8332 bytes
font_01_sfnt_off000057f3.bin
c374740700516b41f218ce1f3063ed30c57c5df665187242c67f0d0be227b05e
pdf-font-stream PDF embedded font (sfnt) at offset 0x57F3 16364 bytes