Malicious PDF — malware analysis report

Static analysis result for SHA-256 a30e7206cd5bb3a1…

MALICIOUS

PDF

195.9 KB Authoring application: PDF Studio
MD5: 9046861c321043d3c339f9a0eaf34b88 SHA-1: d11cc084114cd48f798c5cbe17eac57f2e4770f7 SHA-256: a30e7206cd5bb3a1a741d0044d5966fd7a329c6f0a1f7075231c6445ae78337d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The document body presents itself as a guide for 'Grand Theft Auto: San Andreas' cheat codes, a common lure for phishing and malware distribution. The PDF contains multiple embedded URLs, one of which is flagged as an external URI, suggesting it may lead to further malicious content or downloads. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports the malicious nature of this PDF.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://aero-vodochody.net/uploads/1/3/0/5/130589100/f8b3baf13e65.pdf
    • http://rochesterbiochem.com/uploads/1/3/0/6/130639510/40dfa65f7b.pdf
    • http://ahsyoungbreeders.com/uploads/1/3/0/4/130477541/lobafit.pdf
    • http://nuevaconciencia.info/uploads/1/3/0/7/130775744/5275957.pdf
    • http://yourmoviepal.com/uploads/1/3/0/8/130874511/b1dfb6473e1f4c1.pdf
    • http://mrpsmathclass.com/uploads/1/3/0/3/130323131/lopuduxanupexop-tewotamug-xipijupof-lijexo.pdf
    • http://mhentscheldesigns.com/uploads/1/3/0/6/130640094/1295358.pdf
    • http://nupelicanparty.org/uploads/1/3/0/6/130604433/130604433.html#grand+theft+auto+san+andreas+cheat+codes+money

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000013fd.bin
19dcfc4823fa853ed35d2746d4f152a9b462f01babc04c9e605d027378312845
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FD 9588 bytes