Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5a3465812e2b79d…

MALICIOUS

PDF

45.6 KB Authoring application: pstoedit
MD5: 3f593c28f31662d0e95ba290c7b666df SHA-1: a98a9a4ee00379730eaec412e10a6ed7eb5299a3 SHA-256: e5a3465812e2b79d80c85fbf05000d396b0424327b6d225f0d862ea322281099
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF document that contains multiple embedded URLs. The ClamAV heuristic 'Pdf.Phishing.TtraffRobotInstall-7605656-0' strongly suggests a phishing campaign. The embedded URLs likely lead to further malicious content or phishing pages, aiming to trick users into downloading additional malicious files. No scripts were extracted from this sample.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://canadian-photography.ca/uploads/1/3/0/5/130550693/xefosinigutomobezize.pdf
    • http://alicevonlindenau.com/uploads/1/3/0/6/130620880/7779360.pdf
    • http://misshufnagel.com/uploads/1/3/0/5/130542935/ba5614.pdf
    • http://pcotechnologies.com/uploads/1/3/0/2/130288986/fikekusadakif.pdf
    • http://rightofwaysolutionsllc.com/uploads/1/3/0/6/130620990/d30d5.pdf
    • http://miracleinabucket.com/uploads/1/3/0/7/130775665/130775665.html#sas+import+excel+all+sheets

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010e0.bin
88d5e0a505319f99c4239406004f38cd580398b6e57bd2f132c6ac26e2989e41
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E0 9048 bytes
font_01_sfnt_off00006c8b.bin
779aa567746046747dac965df7fdfb06ff632674a0a99ce247a327bf89f0fa63
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C8B 16036 bytes