Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7a908a6e14ed08a…

MALICIOUS

PDF

32.6 KB Authoring application: QPDF
MD5: 4083005a1414d566286cde7138ce3002 SHA-1: 81f6f79cfd082714f4f8a7bf43ca6c6e90fefde6 SHA-256: c7a908a6e14ed08aea9c76122573808979a61a4a25b16389fc7a6f510d95891e
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The ClamAV heuristic 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly indicates a phishing or malware distribution campaign. The presence of multiple embedded URLs, including one pointing to a PDF file, and a visual 'download button' heuristic further support this. The document body, though heavily obfuscated, contains references to these URLs, suggesting they are the intended targets for user interaction.

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://eastelephant.us/uploads/1/3/0/4/130490719/2d8d719946.pdf
    • http://ithinkevents.com/uploads/1/3/0/2/130271212/5530010.pdf
    • http://nyclanguageinstitute.com/uploads/1/3/0/5/130551239/ca94d2286.pdf
    • http://opusjobs.net/uploads/1/3/0/6/130639949/porobofusaz.pdf
    • http://woodlandstuition.com/uploads/1/3/0/4/130435544/130435544.html#ap+transport+rc+card

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00000faf.bin
46ee11b29e31882ce2c1cec78f12f6cb9ae244e525912bbc6e50a69803c8456c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAF 7776 bytes