Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfc02e0d6d1eae5a…

MALICIOUS

PDF

34.1 KB Authoring application: SWFTools
MD5: 671fe7962fde82254c184a6bfe713eed SHA-1: bd31d9e67c37f0228e69f18b74c950b219aa11c0 SHA-256: cfc02e0d6d1eae5a5017a5c7956cf698dafea937944c518610363f89c3104af3
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is a PDF document that contains multiple embedded URLs pointing to other PDF files. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the presence of external URIs strongly suggest a phishing or malicious content delivery attempt. The document body, though partially corrupted, mentions 'Sentence completion exercises with answers pdf', indicating a lure to download further malicious content.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bowls.ws/uploads/1/3/0/4/130488498/275016.pdf
    • http://nhatrangpartytown.com/uploads/1/3/0/4/130488696/ximimimufemujivosame.pdf
    • http://michaelwarrenmurphy.com/uploads/1/3/0/5/130541313/c188489d2fc.pdf
    • http://fugo.cargo-floor.ru/uploads/2020/01/28/648d1083.pdf
    • http://polozoffdesign.com/uploads/1/3/0/5/130540280/gibogozeru.pdf
    • http://5pointauto.com/uploads/1/3/0/5/130539403/130539403.html#sentence+completion+exercises+with+answers+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001094.bin
da86aac497283dc334872601fc4c4d3dc1ce9c1b154572d7abf044040ecfef13
pdf-font-stream PDF embedded font (sfnt) at offset 0x1094 8312 bytes