Malicious PDF — malware analysis report

Static analysis result for SHA-256 4becd829dbe99a7c…

MALICIOUS

PDF

217.0 KB Created: 2021-01-15 05:02:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: 300c8e6cc9802dbd12a9d2274558b97f SHA-1: 70ef496ddd58bb23790c0febbf007e3d1e4e8495 SHA-256: 4becd829dbe99a7cd65ad2ccd0a22f58729b524a1567bffc820ccb4ec85af7b8
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as a malicious PDF by ClamAV and an ML classifier, with heuristics indicating the presence of external URIs and urgency lures. The document body, though heavily obfuscated, contains text related to 'One direction x factor' and authoring application details, suggesting a potential lure. The embedded URL 'https://trafftec.ru/123?utm_term=one+direction+x+factor' is a primary indicator of a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9770

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/123?utm_term=one+direction+x+factor PDF link annotation
    • https://jevamupoledi.weebly.com/uploads/1/3/4/7/134712268/lezanos.pdfIn PDF document text
    • https://site-1174506.mozfiles.com/files/1174506/hppsc_answer_key_allied_2016.pdfIn PDF document text
    • https://terarawuterojuz.weebly.com/uploads/1/3/0/7/130739827/fulebufuluxasarifaka.pdfIn PDF document text
    • https://site-1178710.mozfiles.com/files/1178710/dupevifezivefulogutugi.pdfIn PDF document text
    • https://mazogerivajusem.weebly.com/uploads/1/3/4/3/134341978/nepefekapuk-pezanefeza.pdfIn PDF document text
    • https://busuguzokiw.weebly.com/uploads/1/3/1/4/131406797/7325279.pdfIn PDF document text
    • https://site-1173576.mozfiles.com/files/1173576/flight_club_chicago_happy_hour.pdfIn PDF document text
    • https://site-1183131.mozfiles.com/files/1183131/nulanupanipajefezede.pdfIn PDF document text
    • https://rugisuvo.weebly.com/uploads/1/3/4/4/134438002/vuras.pdfIn PDF document text
    • https://site-1168306.mozfiles.com/files/1168306/bexan.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/moduluzuxikari/chinese_fonts_for_windows_10_free.pdfIn PDF document text
    • https://s3.amazonaws.com/pisik/74667266444.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002fdd3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2FDD3 3956 bytes
SHA-256: 2e0a36ccb117b01863a2ce7868907c82ad50ee54418b8e0f88735b367d6701d9
font_01_sfnt_off00030bc3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x30BC3 4900 bytes
SHA-256: 015827e0d007e1385c8c6440fa86c23cbfb124506bc93cb44024bad543c1db77
font_02_sfnt_off00031c77.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x31C77 1912 bytes
SHA-256: e9f8a3ef788f0cbd16162dfcacf3538d4d9f72d83e44e67f72eb93bd53224865
font_03_sfnt_off000325a6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x325A6 13832 bytes
SHA-256: 89c7ecbdf046e665538728f58f9a1282e513b6661720944efe65a7e046862074