Malicious PDF — malware analysis report

Static analysis result for SHA-256 3500a97d6c0ce767…

MALICIOUS

PDF

69.7 KB Created: 2020-11-25 18:14:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2319792b3310bb1ae491b5ffd0850739 SHA-1: d6bbaffe74abb46c70c279a30103dd24bcad67f5 SHA-256: 3500a97d6c0ce7679da69acf4d2069d0f3c40f36e3bcc5316d46fe5d8f480a5f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by ClamAV as a phishing trojan and by an ML classifier with high confidence. It contains an embedded URL pointing to 'trafffi.ru', which is likely malicious. Although no executable scripts were found, the presence of the malicious URL and the document's classification strongly suggest it's used for phishing or to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=sas+current+date
    • https://cdn-cms.f-static.net/uploads/4393763/normal_5f9b48c622be8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/87dd668d-4283-495b-a580-a3a9820cb73e/kitchen_number_1_bridgeport_connecticut.pdf
    • https://uploads.strikinglycdn.com/files/97ba0abf-be58-43cf-8c79-5e5b33726d69/difference_between_project_and_program_with_example.pdf
    • https://uploads.strikinglycdn.com/files/443d56a1-2d38-40e6-9c4e-2942aa9c157b/brevig_mission_school_alaska.pdf
    • https://uploads.strikinglycdn.com/files/52acba99-60d2-474a-8e4d-a8f40c632dc7/thermodynamics_an_engineering_approa.pdf
    • https://uploads.strikinglycdn.com/files/6682185b-6914-4aeb-ae1c-6155220ce8c8/virapevovumozawanalifumul.pdf
    • https://s3.amazonaws.com/varolexexus/motorised_valve_actuator.pdf
    • https://uploads.strikinglycdn.com/files/f3131ab5-06e4-491c-a60e-d4cafaf3ebeb/19552316955.pdf
    • https://uploads.strikinglycdn.com/files/ad9b6d0f-95f2-458c-9b49-3d044f422259/toothpickase_enzyme_lab_answers.pdf
    • https://s3.amazonaws.com/fadedosi/80122103791.pdf
    • https://s3.amazonaws.com/fedufiporara/activity_based_learning.pdf
    • https://s3.amazonaws.com/wegugus/4948933055.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c99f.bin
faa4bd6e183aae53ba65f6d2b5ec8cef7717ffb4f2686252bba5453a6c7bd6f1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC99F 5004 bytes
font_01_sfnt_off0000daa2.bin
3c8c70e95e172d87f88249f6e98f5fcd1d779dd22b9512bb6276049fa774e71f
pdf-font-stream PDF embedded font (sfnt) at offset 0xDAA2 1940 bytes
font_02_sfnt_off0000e3da.bin
0a4952b3c779fd660117afe58e13d4ed3b44208912c68979ef0e26b720351df8
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3DA 10812 bytes