Malicious PDF — malware analysis report

Static analysis result for SHA-256 673c18fd1ab4e5ed…

MALICIOUS

PDF

297.0 KB Created: 2021-01-11 12:21:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 30d2fee4019dc9bfee3a86f0d15b8375 SHA-1: 1f60c2d01cbba967cc3a3f4f3f5e2ad069320531 SHA-256: 673c18fd1ab4e5ed506f565feaa8e549b460a3a77371af656c9d8644ed1dcc4a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains an embedded URI pointing to 'trafficel.ru', which is likely used to redirect users to a phishing or malware distribution site. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to exploit users by directing them to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?utm_term=teachers+college+press+publisher PDF link annotation
    • https://rumikupim.weebly.com/uploads/1/3/5/3/135310872/7145484.pdfIn PDF document text
    • https://rigukolanerimi.weebly.com/uploads/1/3/4/5/134519373/63689.pdfIn PDF document text
    • https://dobekaveliwe.weebly.com/uploads/1/3/4/5/134599348/jamufevenelil.pdfIn PDF document text
    • https://vapurexox.weebly.com/uploads/1/3/4/8/134865026/9488940.pdfIn PDF document text
    • https://fekugutupufug.weebly.com/uploads/1/3/4/8/134876907/luvuporogazef_foximila.pdfIn PDF document text
    • https://fipamowusaki.weebly.com/uploads/1/3/4/8/134879766/6380469.pdfIn PDF document text
    • https://larunigilusevim.weebly.com/uploads/1/3/5/3/135320243/rexotiwevukikina.pdfIn PDF document text
    • https://menajogatidufe.weebly.com/uploads/1/3/0/7/130740573/9000576.pdfIn PDF document text
    • https://zasiranel.weebly.com/uploads/1/3/4/5/134507270/9387501.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/xisefowu/arikil_pathiye_hd_video_song.pdfIn PDF document text
    • https://s3.amazonaws.com/kudufigunabi/40869909207.pdfIn PDF document text
    • https://s3.amazonaws.com/tesasubawalozan/gosovojusut.pdfIn PDF document text
    • https://s3.amazonaws.com/sixenogafopoj/tatelebozolikubajivol.pdfIn PDF document text
    • https://s3.amazonaws.com/vuforewebub/43298681010.pdfIn PDF document text
    • https://s3.amazonaws.com/tokit/pdf_file_reader_for_windows_7.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000438d6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x438D6 5284 bytes
SHA-256: 9107520b47586d3efef41eb8b037384bc337e7be1022b3a3d5e4f4f650182343
font_01_sfnt_off00044ac3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x44AC3 17232 bytes
SHA-256: 020bcf68f09f56e05bbb57efb00357d2cab1322ee44e6d88a995b8978db09c4e
font_02_sfnt_off00047f9d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x47F9D 16204 bytes
SHA-256: 532315dfdc59b350d447ad91845dd8cc72a836e684f536ab9a4305dc5b53fb8e