Malicious PDF — malware analysis report

Static analysis result for SHA-256 a30e7206cd5bb3a1…

MALICIOUS

PDF

195.9 KB Authoring application: PDF Studio First seen: 2020-09-24
MD5: 9046861c321043d3c339f9a0eaf34b88 SHA-1: d11cc084114cd48f798c5cbe17eac57f2e4770f7 SHA-256: a30e7206cd5bb3a1a741d0044d5966fd7a329c6f0a1f7075231c6445ae78337d
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The document body presents itself as a guide for 'Grand Theft Auto: San Andreas' cheat codes, a common lure for phishing and malware distribution. The PDF contains multiple embedded URLs, one of which is flagged as an external URI, suggesting it may lead to further malicious content or downloads. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9604

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://aero-vodochody.net/uploads/1/3/0/5/130589100/f8b3baf13e65.pdf PDF link annotation
    • http://rochesterbiochem.com/uploads/1/3/0/6/130639510/40dfa65f7b.pdfIn PDF document text
    • http://ahsyoungbreeders.com/uploads/1/3/0/4/130477541/lobafit.pdfIn PDF document text
    • http://nuevaconciencia.info/uploads/1/3/0/7/130775744/5275957.pdfIn PDF document text
    • http://yourmoviepal.com/uploads/1/3/0/8/130874511/b1dfb6473e1f4c1.pdfIn PDF document text
    • http://mrpsmathclass.com/uploads/1/3/0/3/130323131/lopuduxanupexop-tewotamug-xipijupof-lijexo.pdfIn PDF document text
    • http://mhentscheldesigns.com/uploads/1/3/0/6/130640094/1295358.pdfIn PDF document text
    • http://nupelicanparty.org/uploads/1/3/0/6/130604433/130604433.html#grand+theft+auto+san+andreas+cheat+codes+moneyIn PDF document text
🗂 Part of campaign: jwhammond.com 3 samples

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013fd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13FD 9588 bytes
SHA-256: 19dcfc4823fa853ed35d2746d4f152a9b462f01babc04c9e605d027378312845