Malicious PDF — malware analysis report

Static analysis result for SHA-256 772d4d3a13f703f6…

MALICIOUS

PDF

84.5 KB Created: 2020-12-24 03:23:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-15
MD5: 7ee2db657d714eb9163ecb3f27f40aa8 SHA-1: e97ee1399db823093cf314cc06f40117c22b2e0a SHA-256: 772d4d3a13f703f6838a76b8c65bfd6ed685cd7ff637c7fa422e574ee55a8097
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL, 'https://trafffe.ru/strik?utm_term=project+management+certification+austin+texas', which is likely the primary vector for its malicious activity. Although no scripts were extracted, the presence of the URL and the phishing classification strongly suggest an attempt to trick the user into visiting a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/strik?utm_term=project+management+certification+austin+texas PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4447087/normal_5fb629743b4c0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4449618/normal_5fa25b1fe5fe7.pdfIn PDF document text
    • https://cdn.sqhk.co/nibedogoxov/egjt5gc/knives_for_sale_near_me.pdfIn PDF document text
    • https://pulatufulufu.weebly.com/uploads/1/3/4/6/134610330/nibalisowo.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4423452/normal_5fbd9b25d2c1a.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/9537597e-93a7-467b-9fc8-90429781a48d/33719163961.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e27826d8-7a7c-4175-b6e7-ae25a3ae4549/music_staff_notes_chart.pdfIn PDF document text
    • https://s3.amazonaws.com/kujapomib/android_programming_tutorials_w3schools.pdfIn PDF document text
    • https://s3.amazonaws.com/zodererezuzuxi/case_study_research_design_format.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b4459a6c-4298-474c-9487-fd0a536b01e8/sap_handbook_free.pdfIn PDF document text
    • https://s3.amazonaws.com/jefobexapulow/dnd_5e_drinking_a_potion_action.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010d34.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10D34 5312 bytes
SHA-256: 728d0be818ba9661b9467969ebb1d99de862e2d1b20e7b44303f3e84c3cc25ec
font_01_sfnt_off00011f3d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F3D 11136 bytes
SHA-256: d66477cfc32b15ab50b8dc13c70f9ae90b879f0c7ece061a16fa1a4bfafdb92d