Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3e3c9afb8f941d4…

MALICIOUS

PDF

28.9 KB Authoring application: Nitro PDF
MD5: 7dcd046f4a3c6de89ddaad8149fbf1b7 SHA-1: 45695b0a316ac8773965fd30a8a1a8daf1bd4012 SHA-256: a3e3c9afb8f941d4c824bcd3096b5e9709c450d25ea15db47d5bd77780e626b8
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is a PDF document that contains multiple embedded URLs pointing to other PDF files. The ClamAV heuristic 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly suggests a phishing intent. The document body contains garbled text and some mathematical questions, likely as a distraction or to appear legitimate. The primary attack pattern involves tricking the user into clicking on the embedded links to download further malicious content.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://myersac.com/uploads/1/3/0/2/130287886/1df2cea703cd.pdf
    • http://commandlineidiot.com/uploads/1/3/0/4/130436473/mikowowelivu_jetig.pdf
    • http://nekima.net/uploads/1/3/0/6/130604777/72bc956d.pdf
    • http://mykdphotography.com/uploads/1/3/0/2/130271108/9a4ccce3ec53a.pdf
    • http://blockchainambassador.ca/uploads/1/3/0/6/130604173/130604173.html#in+parallelogram+wxyz%2C+what+is+cy%25

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001016.bin
f89a4d604bdc46d7607d59b96156ae0673d2a1c59c2a09597e1e38377156c90f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1016 8256 bytes