Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0e91fc8bc9edf01…

MALICIOUS

PDF

40.8 KB Authoring application: Soda PDF
MD5: a9c0b64f01cbca01db2d808d485c67eb SHA-1: 9831bd39b5f1de0189e46591872cca03aa1b1661 SHA-256: f0e91fc8bc9edf017d70c6552528abef332c6dc377bbfe177ab0041d739aacdd
70 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1566 Phishing

The file is identified as malicious by ClamAV with the signature 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The document body contains embedded URLs that likely lead to further malicious content, and a heuristic indicates the presence of a visual download button. The primary IOC is the external URI pointing to a PDF hosted on pikespeakseniors.org.

Heuristics 4

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://pikespeakseniors.org/uploads/1/3/0/3/130323571/4023826.pdf
    • http://connectivityusa.net/uploads/1/3/0/2/130288479/pixozariruketuga.pdf
    • https://fawodunod.weebly.com/uploads/1/3/0/5/130540155/wijebibujidites.pdf
    • http://michaelshusko.com/uploads/1/3/0/5/130545396/130545396.html#bridget+jones+diary+torrent

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011cc.bin
3f77ef4c1737256baba44e3ba8ab5a4842980974589268156a1179188b712c38
pdf-font-stream PDF embedded font (sfnt) at offset 0x11CC 8732 bytes
font_01_sfnt_off000056ca.bin
97874a4addc19fa4074745ca041f25e8d04a20388e11e93362cd6d1dee3bfeb1
pdf-font-stream PDF embedded font (sfnt) at offset 0x56CA 16840 bytes