Malicious PDF — malware analysis report

Static analysis result for SHA-256 575940b4150dff64…

MALICIOUS

PDF

82.0 KB Created: 2020-12-02 00:06:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a772659a4a77bfe7b1fcec0f6725cfa3 SHA-1: d0d72cd81a4ea8b243ed1f6bb928b9a5a9f4219b SHA-256: 575940b4150dff641e85af0ef5addbe43e2582a5f557cf63db9fdc98620373aa
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with heuristics indicating it's a PDF with an embedded URI and a potential invoice lure. The embedded URL, https://trafficel.ru/aws?utm_term=budget+2019+current+affairs+pdf, is the primary indicator of malicious intent, likely leading to a phishing page or malware download. Although no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest an attempt to exploit users through social engineering.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=budget+2019+current+affairs+pdf
    • https://cdn-cms.f-static.net/uploads/4366645/normal_5f8b6e016da8f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/7be69cdf-8f25-4a27-80e1-87e7c0260cad/mexepitazulutepi.pdf
    • https://uploads.strikinglycdn.com/files/54d3ccb7-38df-4153-8a12-c6c0dfaeef65/2993511465.pdf
    • https://s3.amazonaws.com/sulasatevirexo/73969231661.pdf
    • https://s3.amazonaws.com/xajowu/dumetevokifimubozipik.pdf
    • https://uploads.strikinglycdn.com/files/7879f73e-aac9-4ae9-af3d-799d9b731735/76860270326.pdf
    • https://uploads.strikinglycdn.com/files/b393d03a-2391-4b27-a4a2-29d82a83c9ce/suwadewekosukuziw.pdf
    • https://uploads.strikinglycdn.com/files/0dce45a6-9c20-4529-baa2-efca452fd8e5/pit_boss_820_deluxe_wood_pellet_grill_manual.pdf
    • https://uploads.strikinglycdn.com/files/22522810-60ab-4483-8535-4f5561c05816/how_to_download_the_espn_app_to_mu_s.pdf
    • https://uploads.strikinglycdn.com/files/53e9afc0-b284-41b3-821e-9abcd7f78a1c/the_myth_of_sisyphus_camus.pdf
    • https://s3.amazonaws.com/wopari/jubenoxumuwup.pdf
    • https://s3.amazonaws.com/mewezekilafef/powerflex_40_manual_espanol.pdf
    • https://s3.amazonaws.com/sedimeraxufi/rivexekokurudilawiwig.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010300.bin
16fe68fd38a71f632ff3e7179618c57d341ff7a5352ebc3c2458f7b7e53ece12
pdf-font-stream PDF embedded font (sfnt) at offset 0x10300 5824 bytes
font_01_sfnt_off000116eb.bin
8e932b191a0e8e9e965823ebd304ea21e8840049e02dd11e2c52b07834136780
pdf-font-stream PDF embedded font (sfnt) at offset 0x116EB 10732 bytes