Malicious PDF — malware analysis report

Static analysis result for SHA-256 26ba92d6799b680f…

MALICIOUS

PDF

67.6 KB Created: 2020-11-10 19:22:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d5df6acc9059815967fb78e52e4e4677 SHA-1: 7242f6afb81fd9e3a625e1293731f035bffaae46 SHA-256: 26ba92d6799b680f1ca146b46637658201cf651286fdac2e867b1e71dfe3f489
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. An external URI pointing to 'traffine.ru' was extracted, suggesting a phishing or malware distribution lure. The PDF structure and embedded content, though partially obfuscated, are consistent with documents designed to exploit vulnerabilities or trick users into visiting malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/aws?keyword=first+poem+for+you+analysis
    • https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/96c09c94888.pdf
    • https://cdn-cms.f-static.net/uploads/4378378/normal_5f8eb8f1b62f6.pdf
    • https://nasotatuji.weebly.com/uploads/1/3/4/3/134392375/78046.pdf
    • https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/2a5b38eef3430.pdf
    • https://cdn-cms.f-static.net/uploads/4373281/normal_5fa4c16786726.pdf
    • https://rokufekajo.weebly.com/uploads/1/3/0/8/130814342/5a27bd4.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/varolexexus/can_gravitational_force_be_negative.pdf
    • https://uploads.strikinglycdn.com/files/f56541c4-0ace-4dec-87ef-5e652bbbba54/84117870641.pdf
    • https://uploads.strikinglycdn.com/files/a30c3ff6-488e-4eff-b2f6-9909f17a7933/kapiw.pdf
    • https://uploads.strikinglycdn.com/files/7ae65700-058c-417f-a726-1f56ae11ebe1/43199559143.pdf
    • https://uploads.strikinglycdn.com/files/978460c1-abe8-4046-885b-899c6104029f/bandicam_email_and_serial_number_2017.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cee9.bin
4034ee75238241c122cb13c9550e6b8249236948454f0901576129a8ca920b7f
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEE9 5104 bytes
font_01_sfnt_off0000e03d.bin
b20c665b280895869d8d073bd6fec518c3313c6d46feb45019a1cdb512c70059
pdf-font-stream PDF embedded font (sfnt) at offset 0xE03D 9888 bytes