Malicious PDF — malware analysis report

Static analysis result for SHA-256 87479393361eca96…

MALICIOUS

PDF

33.9 KB Authoring application: LibreOffice
MD5: 919eacbb5e799c336453f7ef50f4408d SHA-1: ceb776b4306732014399ef34fb12d1a170da54a1 SHA-256: 87479393361eca96103efaeddce5a53d656416940d6fafd2e5946b15076b64f0
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is a PDF document that masquerades as a structural fire safety manual. It contains embedded URLs pointing to other PDF files, suggesting a phishing or malware distribution attempt. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports the malicious nature of the file, indicating it's part of a phishing campaign designed to install malware.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dadopefinavabit.weebly.com/uploads/1/3/0/4/130476611/872595.pdf
    • http://amybournephotography.com/uploads/1/3/0/6/130621197/f31c845e3034472.pdf
    • http://aimztruly.com/uploads/1/3/0/4/130435544/gakezajak.pdf
    • http://mynaturalhairspa.com/uploads/1/3/0/7/130738823/130738823.html#manual+de+incendios+estructurales

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001015.bin
79ee8ff500b4db0b911e1ddbf45a13043577672313a9ef00b94668a1addbb06b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1015 8980 bytes