Malicious PDF — malware analysis report

Static analysis result for SHA-256 8cb77b710dc6314b…

MALICIOUS

PDF

82.4 KB Created: 2020-11-09 19:09:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4af55dc75e8ede069ac4e20e4df5222b SHA-1: 1bc22509aef0f3d82cd1a0083e51edc77733d998 SHA-256: 8cb77b710dc6314b1eafd7c4b88407411266ffa2d9cecbb05a316cc880c862e0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'traffset.ru', which is likely part of a phishing or scam campaign. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffset.ru/aws?keyword=next+womens+tops
    • https://cdn-cms.f-static.net/uploads/4377936/normal_5f8b19574c8eb.pdf
    • https://cdn-cms.f-static.net/uploads/4379473/normal_5f9f3b9580dde.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/8765a71d-5f16-49cc-8ab8-7fc174382670/study_guide_for_bradburys_a_sound_o.pdf
    • https://uploads.strikinglycdn.com/files/54e86556-a97b-4793-bcee-0948eb8585fa/to_strike_the_last_word_meaning.pdf
    • https://uploads.strikinglycdn.com/files/3f6afa47-b6a6-4caa-aa09-8505501d78f3/zitamalesojakabigowexav.pdf
    • https://uploads.strikinglycdn.com/files/e0b479a4-b68d-45fe-a77e-928f31aa9fab/zalizeda.pdf
    • https://uploads.strikinglycdn.com/files/0b584b2d-85db-435d-ab1e-cef605ad74bc/xv2_mods_installer_download.pdf
    • https://uploads.strikinglycdn.com/files/7bda5a1f-8965-40ab-a3ca-755391c597bb/newarabi.pdf
    • https://uploads.strikinglycdn.com/files/8c1b962b-3a34-4b4b-a05a-c3be0f5501b3/35267549070.pdf
    • https://uploads.strikinglycdn.com/files/860e296e-0e6f-4323-9f3b-c686cda6d267/vinesoludobaxalolukewuwu.pdf
    • https://uploads.strikinglycdn.com/files/536dcfc8-e198-46aa-8c49-fbdfdfb808c0/gogatiwuzupebewuvexi.pdf
    • https://uploads.strikinglycdn.com/files/94ced9b2-031b-4f71-91dd-9580f0a1e11c/24514346830.pdf
    • https://uploads.strikinglycdn.com/files/78fa5739-ac84-4165-935e-78b908934953/30908152550.pdf
    • https://uploads.strikinglycdn.com/files/c4460491-8811-4cb6-a8ee-3006f12e16cf/multifidus_muscle_cracking_sound.pdf
    • https://uploads.strikinglycdn.com/files/0dc97898-6c35-4c37-9323-f8916eba8e0b/geometry_second_semester_final_exam_review_answers.pdf
    • https://uploads.strikinglycdn.com/files/cb509c9f-4947-49aa-95dd-4f996aa8b91e/sofufokasabupasur.pdf
    • https://uploads.strikinglycdn.com/files/9434b6db-7a81-4c7a-8940-605cbc2cbf36/56700248392.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001076a.bin
8043f17052d8743ee8de97b6f437166c72fbeaa6576849eed0c3321f81785c72
pdf-font-stream PDF embedded font (sfnt) at offset 0x1076A 4756 bytes
font_01_sfnt_off000117a9.bin
21074b4598d1518d83cedb1a3d23f23ecec69541033a647e05af4b13f3973bc6
pdf-font-stream PDF embedded font (sfnt) at offset 0x117A9 10984 bytes