Malicious PDF — malware analysis report

Static analysis result for SHA-256 c66609fa80452f5f…

MALICIOUS

PDF

35.8 KB Authoring application: Adobe PDF Library 9.0
MD5: 45f3112667e81282c84d4a2efaa90af3 SHA-1: 519c609921e9f6dca7e90632a2ce5a69fa557e6e SHA-256: c66609fa80452f5f5657c0abc24db97f193bf82289527a7ba98b103b3e9c19de
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The file is a PDF document that contains multiple embedded URLs. The ClamAV heuristic indicates it is likely a phishing or malware delivery attempt. The document body, though partially corrupted, mentions 'RFID door lock access control system install' and includes several URLs that appear to be lures for downloading further malicious content. No scripts were extracted from this sample.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://zionlutheranclark.com/uploads/1/3/0/6/130621351/rurulekikat-pasabilalave-bunubafik-jokesesog.pdf
    • http://resurrectionofarunner.com/uploads/1/3/0/2/130287842/dawivate-guliluruxisop.pdf
    • http://cataniainunclick.com/uploads/1/3/0/8/130815228/356517.pdf
    • http://dropdeadgorgeousbybrittany.com/uploads/1/3/0/2/130272318/df63831b52f5382.pdf
    • http://miam-foundation.com/uploads/1/3/0/6/130621622/130621622.html#rfid+door+lock+access+control+system+install

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010ba.bin
54139632885c657dd32682c000b121f926648a7827c8c76ad6684457cf97cddf
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BA 8740 bytes