Malicious PDF — malware analysis report

Static analysis result for SHA-256 e993f290a8202fde…

MALICIOUS

PDF

35.8 KB Authoring application: OpenOffice.org
MD5: 8a85ae0c74d7b4e84c5c9819803d7afd SHA-1: 6b7125caf3e5baf5d242ec29cf54b430bf9446d8 SHA-256: e993f290a8202fde62bf3eed07ce3a91e714952893d5f735310c204644a4fc11
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The ClamAV heuristic indicates this PDF is a phishing lure, specifically identified as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The document body, while containing garbled text, mentions 'Do you want to build a snowman sheet music pdf' and includes multiple external URLs pointing to PDF files. These URLs are likely part of the phishing campaign, aiming to trick users into downloading further malicious content.

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://vobaf.guarchibao-fatcaps.info/uploads/2020/01/28/7776096.pdf
    • http://ziti.vipiska-egrn-besplatno2.icu/uploads/2020/01/27/rarikusiwifiw.pdf
    • http://villagearch.com/uploads/1/3/0/6/130604588/loxamusofoka.pdf
    • http://ruxod.galaxytools.ru/uploads/2020/01/29/vegugobakakukaja.pdf
    • http://heavensgatescherryfarm.net/uploads/1/3/0/3/130323937/61a0c60.pdf
    • http://iweargreatness.com/uploads/1/3/0/4/130489475/130489475.html#do+you+want+to+build+a+snowman+sheet+music+pdf

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000108a.bin
2f551493320e3bc89eb2b6c6ad7fbcc36edfef0293969049735ca894d1f58059
pdf-font-stream PDF embedded font (sfnt) at offset 0x108A 9548 bytes