Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0cdc525f7bd38a0…

MALICIOUS

PDF

52.0 KB Authoring application: OpenOffice.org
MD5: 4544e04d03e3e5c4b5886b789eb3a223 SHA-1: 761ed3dc252cb029bf3ec5796ab5828d13fb6bd6 SHA-256: b0cdc525f7bd38a0e99f226c7df659c3b193312f67dd011abc59d95236c68f50
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The ClamAV heuristic indicates this PDF is a phishing lure. The embedded URIs point to external PDF files, suggesting the document's purpose is to trick the user into downloading further malicious content. No scripts were extracted, limiting the ability to determine the exact payload delivery mechanism.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pastmaster.org/uploads/1/3/0/5/130539756/d410687b18924d1.pdf
    • http://morris-imports.com/uploads/1/3/0/5/130588388/jobegulevorer.pdf
    • http://geves.lcmevents.com/uploads/2020/01/27/226c942.pdf
    • http://nitchtechnologies.net/uploads/1/3/0/4/130476691/tupegosifup.pdf
    • http://nuobeijing.devsite-1.com/uploads/1/3/0/2/130273978/130273978.html#thu%E1%BB%91c+cephalosporin+th%E1%BA%BF+h%E1%BB%87+5

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000125a.bin
d486c897b7f6c0084da62edf7ef1fc32f0c1383460b9ce6ef9b10a3c8e86eb06
pdf-font-stream PDF embedded font (sfnt) at offset 0x125A 10420 bytes
font_01_sfnt_off00007155.bin
27aad4e7100ae85831cc1a9cf4859e84521ff6b1ee9ac199fa10e6c4d4b25dad
pdf-font-stream PDF embedded font (sfnt) at offset 0x7155 2736 bytes
font_02_sfnt_off00007c14.bin
7d9a23cbf7c281bd230484363cc0a59a69fffe5537f55ec201a573cfb55e6f79
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C14 23740 bytes