Malicious PDF — malware analysis report

Static analysis result for SHA-256 c672cae29cfcaef8…

MALICIOUS

PDF

34.1 KB Authoring application: Poppler-utils
MD5: 58034a75dd0cae16dda6664e2fada3bf SHA-1: 606440efaa8c77851e5d3a439eb34d336a5fcaf7 SHA-256: c672cae29cfcaef8f6c9143ae24a2f129bf78a546822046cf37b9da50a15ee7d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The ClamAV heuristic indicates this PDF is associated with phishing, specifically a TtraffRobotInstall variant. The document body, though heavily obfuscated, contains URLs that likely serve as lures for further malicious content. The presence of an embedded PDF URI further supports the attack pattern of delivering malicious content via a seemingly legitimate document.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vetujanali.weebly.com/uploads/1/3/0/4/130435514/wipujujit.pdf
    • http://nicolas-rigaux-photographe.com/uploads/1/3/0/5/130588845/2969000.pdf
    • http://karkakclab.com/uploads/2020/01/29/sunobara.pdf
    • http://stokesed508webpage.com/uploads/1/3/0/3/130312974/130312974.html#difference+between+variable+cost+and+marginal+cost

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000f84.bin
dd7a7d8d40c436715f5d5ec4abd8604d723c2077c87d1fbd119d6d012ba4d8f9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF84 7132 bytes