Malicious PDF — malware analysis report

Static analysis result for SHA-256 86a2c68949800475…

MALICIOUS

PDF

179.9 KB Authoring application: ImageMagick
MD5: 5287695950004411de1b540a08f8cb8d SHA-1: eb89a21d86300a6c34bcb10cd7b80226797e1298 SHA-256: 86a2c68949800475b2bdaf8ed5e715e6a70b4e6b769528f5002b22146aba137f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF containing multiple external URLs, identified by the PDF_URI heuristic. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly suggests a phishing or malicious redirection campaign. The embedded URLs are likely used to host further malicious content or redirect users to phishing pages. No scripts were extracted from this sample, limiting the ability to determine specific execution behaviors.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bsafet.net/uploads/1/3/0/3/130324418/dumexipusupupesanaj.pdf
    • http://dcmserviceinc.com/uploads/1/3/0/2/130289655/dozuni-verezugovalen.pdf
    • http://webmail.chrissieparker.com/uploads/1/3/0/8/130874077/504877d243dc4b7.pdf
    • http://christlife.blog/uploads/1/3/0/5/130588529/1616966.pdf
    • http://gameandsoft.store/uploads/1/3/0/3/130313031/nefoxiso_mesevaz.pdf
    • http://yourluvyoga.com/uploads/1/3/0/3/130313274/masebidov.pdf
    • http://cottageandcheese.com/uploads/1/3/0/8/130813903/zujodazogilizozilimu.pdf
    • http://mta-sts.tampereenfreet.net/uploads/1/3/0/7/130776607/1db1bb55.pdf
    • http://www.paulelderlocal290.com/uploads/1/3/0/7/130739552/tugodobip.pdf
    • http://crankybaker.com/uploads/1/3/0/4/130488542/mituzinenujufetawad.pdf
    • http://socialsnapphotoboothlasvegas.com/uploads/1/3/0/4/130488227/temubivotazas_bidim_zubiliguvalibe_fasobijub.pdf
    • http://webdisk.mindfulday.org/uploads/1/3/0/8/130874163/denifinebopotokidoz.pdf
    • http://vega-music-group.com/uploads/1/3/0/6/130604447/nimavinezoki.pdf
    • http://bucketlisthacks.com/uploads/1/3/0/5/130540402/857d0.pdf
    • http://e4mafiacoffeecompany.com/uploads/1/3/0/2/130289782/6278902.pdf
    • http://wildywell.com/uploads/1/3/0/3/130313433/1983859.pdf
    • http://visionpolaris.com/uploads/1/3/0/4/130489123/pebibozubamimud_zufotosiwi_kefejekobisoji_fujitogutuwevek.pdf
    • http://cranstonroofingservices.com/uploads/1/3/0/6/130620649/e8508452d691.pdf
    • http://wet4u.net/uploads/1/3/0/6/130622120/4fc57e3d1a12a.pdf
    • http://duplexdoctor.com/uploads/1/3/0/4/130476563/pinusenok.pdf
    • http://rep-christ.com/uploads/1/3/0/6/130621803/vafepu.pdf
    • http://noxanima.com/uploads/1/3/0/5/130589095/xewuwerokomavubonol.pdf
    • http://mywholelifeisshirts.com/uploads/1/3/0/5/130589309/gariwepukumozifoxe.pdf
    • http://baudlbears.com/uploads/1/3/0/2/130289421/7971825.pdf
    • http://www.renustone.ca/uploads/1/3/0/7/130740292/xumigufufobogew.pdf
    • http://bshppopup.com/uploads/1/3/0/8/130873829/130873829.html#english+and+amharic+alphabet+pdf
    • http://cottageandcheese.com/uploads/1/3/0/8/130813903

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000022c6.bin
99348fdcb8c5b34425e6c6d02c8e005a8370c1b3d012a7b27603a5b46407e42c
pdf-font-stream PDF embedded font (sfnt) at offset 0x22C6 19012 bytes
font_01_sfnt_off0000445a.bin
bf11fd7257a3ff296c9701d4c5e5b5a0a4d051a5636c7ae6b86d3a2062a46768
pdf-font-stream PDF embedded font (sfnt) at offset 0x445A 11080 bytes
font_02_sfnt_off0001468c.bin
32bffed910ea6ccafb0eaa48b79711e7839d10b8596bf2a67ea79487d6c63db1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1468C 20732 bytes
font_03_sfnt_off00016543.bin
a019e1f040155e6822006c01897c3a327628c2ae71222fcecd9433cac78e864c
pdf-font-stream PDF embedded font (sfnt) at offset 0x16543 3084 bytes
font_04_sfnt_off000178a6.bin
39388973bcadcaed546ceb4cc011b49bea3d07820dcf957dec57aa30fff88a56
pdf-font-stream PDF embedded font (sfnt) at offset 0x178A6 127396 bytes