Malicious PDF — malware analysis report

Static analysis result for SHA-256 826130cbe6cf1b33…

MALICIOUS

PDF

68.8 KB Created: 2020-11-18 08:52:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-05
MD5: 1630a3f4ef88f77f80f5073cee836814 SHA-1: 01a781c68f923b1a2ea54b4df317be5dfc87778b SHA-256: 826130cbe6cf1b3357f8f172b08e65d9e95ff8d62c115a0d43052e7ff1cb0afa
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, 'trafffi.ru', which is likely used to host a malicious payload or phishing page. The document body, though partially garbled, suggests a lure related to a 'Guide to Lisbon'. No scripts were extracted, but the presence of an external URI in a malicious PDF strongly indicates an attempt to redirect the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=guia+lisboa+en+3+dias PDF link annotation
    • https://zudovizu.weebly.com/uploads/1/3/4/3/134338339/zojipefus-siviso.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4483591/normal_5fac1e0c6fdce.pdfIn PDF document text
    • https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/58954.pdfIn PDF document text
    • https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdfIn PDF document text
    • https://fodibiwowi.weebly.com/uploads/1/3/4/4/134479135/dikedoxamida.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393506/normal_5fb34f4c57bab.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/7fc445f4-a145-4464-b8b1-c374a2c04dfb/catalizador_en_ingles.pdfIn PDF document text
    • https://s3.amazonaws.com/bubeto/17137033277.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5ba4daee-a745-4635-971b-8ea63d6c2d6d/viridolagazeratitanem.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d98a4f93-2c5d-411c-95f6-4ccebcbe0a7f/98153705593.pdfIn PDF document text
    • https://s3.amazonaws.com/salade/bhagavad_gita_yatharoop_hindi_free_download.pdfIn PDF document text
    • https://s3.amazonaws.com/subud/antimanual_de_filosofia_onfray.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c98a3bf7-d7d1-4a5f-82a6-9911c9e7b2e2/deduvevugasapo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/08cf2ed0-6a7f-4eb9-b521-47127477b496/binorogumosajisawate.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/700a6338-d602-4456-940f-5c5ebd98759e/vasuropuro.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ee1f772d-6207-4d07-964d-0af22d618b72/harrius_potter_et_philosophi_lapis.pdfIn PDF document text
    • https://s3.amazonaws.com/jodabiladezot/bapetobipuwe.pdfIn PDF document text
    • https://s3.amazonaws.com/rogugagatuf/itinerary_template_pages.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ce07.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCE07 5060 bytes
SHA-256: 166699656628f3e78ef584fe717b2f250c5fdb0dc395c8629095a36e3d7e74e8
font_01_sfnt_off0000df4c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDF4C 11956 bytes
SHA-256: 10da9578912327ecf77792a01eeb119ad58be9cbc3fdf08713f35626a700a6d2