Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf8752635c842781…

MALICIOUS

PDF

24.0 KB Authoring application: OpenOffice.org
MD5: 6178cd67e1e181f3dfb9ee8a308a1345 SHA-1: 838a2fa3879dce3e56061df20d71347958cdf4a4 SHA-256: bf8752635c8427818611e02a63a861988d8481b4ae3843c9b2b5db4f9481431b
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The file is a PDF document identified by ClamAV as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. It contains multiple embedded URLs pointing to PDF and HTML files hosted on various domains. These URLs are likely used to deliver phishing content or download further malicious payloads. No scripts were extracted from this sample, limiting the ability to determine specific execution methods.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://missinglinkbrewing.net/uploads/1/3/0/3/130323173/wulozurelidu_naxek_kamipu_wajomusefamo.pdf
    • http://neurocogconnect.org/uploads/1/3/0/3/130323469/2110633611f8204.pdf
    • http://nirunutrition.com/uploads/1/3/0/4/130488312/c9f2db.pdf
    • http://mobyrapid.com/uploads/1/3/0/5/130543057/159065.pdf
    • http://uvcheer.com/uploads/1/3/0/3/130324278/641d42.pdf
    • http://cityonloc.com/uploads/1/3/0/6/130621352/130621352.html#android+floating+action+button+textview

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f4b.bin
48f62dec5148fb723df14f0e61d1688d5529b9ba161ce207048fe845e5cb0cf9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4B 5324 bytes