Malicious PDF — malware analysis report

Static analysis result for SHA-256 e64d056e5cb4bd5f…

MALICIOUS

PDF

40.2 KB Authoring application: Poppler-utils
MD5: 6bc0af18624ccc9c0876d6ef9e58975a SHA-1: d554504a34aa265a99b5f9a3868478e84efac1c0 SHA-256: e64d056e5cb4bd5f0be33a6937280e035dd4e25ddeaa0453d26b8a29ca6a53a5
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The ClamAV heuristic 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the presence of multiple external URIs within the PDF strongly suggest a phishing campaign. The document body, though partially garbled, mentions 'Alimentos permitidos dieta acido urico', indicating a lure related to health or diet information. The embedded URIs likely point to further malicious content or payloads.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://michiganroofmasters.com/uploads/1/3/0/4/130488091/rozoraput.pdf
    • http://radikal4kidzinc.org/uploads/1/3/0/4/130476688/rozizuretu.pdf
    • http://kathleenmaree.com/uploads/1/3/0/4/130489465/wunotoxefexosuro.pdf
    • http://allesaker.com/uploads/1/3/0/8/130814845/670b67fc80c7.pdf
    • http://carrielcopeland.com/uploads/1/3/0/3/130313356/6360468.pdf
    • http://mynaturalhairspa.com/uploads/1/3/0/7/130775504/130775504.html#alimentos+permitidos+dieta+acido+urico

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000010bd.bin
0f2fc2759ecad34a356a5a0a2f7f5bd3b896b630aa22a710f8631586392434cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BD 9816 bytes