Malicious PDF — malware analysis report

Static analysis result for SHA-256 88a6f032a165b762…

MALICIOUS

PDF

63.1 KB Created: 2020-12-16 13:45:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-02
MD5: 3cd5d97e4e81ed2515ff857464e9db6f SHA-1: 704e22ff5d0f0c901f33f75dd2efe874e05300fe SHA-256: 88a6f032a165b762e076da3712ed90f3a619cf2178e57a29cb281b64b89086a2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'traffset.ru', which is likely a lure for users seeking free software. The document body, though heavily obfuscated, suggests a context related to 'mix master bpm analyzer free', reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?utm_term=mix+master+bpm+analyzer+free PDF link annotation
    • https://gokopawe.weebly.com/uploads/1/3/4/4/134493337/4589730.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4459479/normal_5fbf0c84ae68a.pdfIn PDF document text
    • https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/b14d3bbae9.pdfIn PDF document text
    • https://dopozigixojak.weebly.com/uploads/1/3/4/5/134509916/3677086.pdfIn PDF document text
    • https://tubenuluni.weebly.com/uploads/1/3/1/4/131437864/lafuximojexa.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/23d987df-d679-46db-98e4-29797cefeb2e/magnifique_est_le_seigneur.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f41a643e-ee2d-4a8e-a55e-7af8c4a5fd3b/johnsonite_rubber_wall_base_epd.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc2b498e9fc3622d52dc1d8/t/5fc4506a6457125654c59ad5/1606701162885/senifesajipesepena.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f8e6e353-fa11-4eaa-b358-9d32767ad3cb/zenobia_summoners_war_reddit.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/04548fc3-b0e9-4789-beb7-711b4bab1499/83936066038.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc7acc6a4492a057e24fcdc/t/5fd1c27afec2791e3106dbc0/1607582335682/25878855473.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc37a0f11f6a419849608d5/t/5fc5fc347acac6192a900a36/1606810677699/mlb_home_run_derby_date.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b82986bf-7ec2-4c79-b018-9291c5a5dcdf/free_colon_and_semicolon_worksheets.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8237d6b8-433e-474f-9bcc-ab84fe352384/libros_catolicos_gratis_para_descargar_en.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ba2d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBA2D 5412 bytes
SHA-256: 816dbebbc8a743ed7a4e55ba57421db3d3643146461edf3812150d1ec496b17a
font_01_sfnt_off0000cc9c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCC9C 10472 bytes
SHA-256: 7edd9e37311f408099c232ea97ae99431cfd18246879ce97ff334eb7426767ac