Malicious PDF — malware analysis report

Static analysis result for SHA-256 9df3ecdc6d8c9868…

MALICIOUS

PDF

61.5 KB Created: 2020-12-13 14:40:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 538b6bb16a160f5458731f898d15bd1a SHA-1: d65531e3e640cb76a382ad9bb579f1d294709632 SHA-256: 9df3ecdc6d8c9868653aa81fccb0db97f7ee710355641f057864646a0b9e02a6
76 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF document contains a heuristic indicating a lure to install a browser extension or update, a common social-engineering tactic. The ML classifier also flagged the PDF as malicious with high confidence. An external URI was found pointing to 'traffking.ru', which is likely part of the payload delivery or C2 infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/strik?utm_term=fx+derivatives+trader+school+review PDF link annotation
    • https://foposivore.weebly.com/uploads/1/3/4/4/134472686/4630480.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4392666/normal_5f9eb88ce59f9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370068/normal_5f9bec51820b9.pdfIn PDF document text
    • https://fexejazawipezes.weebly.com/uploads/1/3/4/8/134869354/1429717.pdfIn PDF document text
    • https://garagagu.weebly.com/uploads/1/3/4/3/134364865/tipakapevozit.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://static1.squarespace.com/static/5fc4dac4ec917750a3f10bd2/t/5fc707530791337046daba3a/1606879062053/easy_nail_art_designs_at_home_without_tools.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe23d9173fb5383b6b3b93/1606296538928/23547136379.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc137400b6b03258f37a4df/t/5fc84cef7ff5a343ebf0af0d/1606962416749/fowozopizazeda.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/44d184db-0eb4-4f86-8d1f-b06126d4a73a/66251674232.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d6d0c07b-d728-41ce-82ac-c7e645876bcc/mojunexanedurovi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f6554876-8f1f-4f63-a633-d49f03dc87c7/77484912662.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b5fb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB5FB 5204 bytes
SHA-256: 3bf4cb979431dbac5750a106f483fcb76c738eb1b3584694ed8a3c425a34b7fa
font_01_sfnt_off0000c7bd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC7BD 9924 bytes
SHA-256: 4c4266c6aac5a0edfa2a3cf568ff84817654ab2c705ad51566a89d5d1ed95e2a