Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba1443733e4a53c4…

MALICIOUS

PDF

70.6 KB Created: 2020-12-06 09:53:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: e9c0f1ac82782e43a5754c8ac1e21ed7 SHA-1: f0f914a61b791a09e5e767cb6efcde57efa13bee SHA-256: ba1443733e4a53c4294ad0cc33b99fc93c44e6edb00131597bba1cf1a2701a02
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document identified as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to 'trafftec.ru', which is likely a phishing or malware distribution domain. The document body appears to be corrupted or obfuscated, but the presence of the external URI and the overall detection strongly suggest a malicious intent, possibly related to phishing or delivering a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/aws?utm_term=betagro+annual+report+2018 PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4379744/normal_5f9f234c21025.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412161/normal_5f9fbbec69030.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383445/normal_5fb4f172e39fb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4486997/normal_5fbbe6eea2e99.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c83ff1f3-e9b0-4b2c-8fd4-6186d090ad94/masebasefaxarizunid.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc0d92f11f6a4198485658d/t/5fc3eedaeaf37e3b6415c00b/1606676187775/velules.pdfIn PDF document text
    • https://s3.amazonaws.com/purawuma/cours_algorithme_bts.pdfIn PDF document text
    • https://s3.amazonaws.com/falevi/72301852669.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dae0fff3-daa5-415b-96b2-0c8f15d9eeaf/minecraft_recipe_book_mod_1.12.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe15feeaf37e3b6463c266/1606292991931/vodub.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1aaabbd4-0f63-4dd5-820e-6c1d75b04c61/5411932938.pdfIn PDF document text
    • https://s3.amazonaws.com/tadovu/wuwalafuk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/643f7ba0-a335-4b8c-a526-02539943c905/97467255594.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dbb5cd7a-23b5-481c-b886-18f262945bdd/51860692548.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc285aae5c7695ca9a5ff19/t/5fc6df69a907d7439cca08d5/1606868844624/communism_vs_capitalism_debate.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf51cdfa04221c71170ed1/1606373838803/kidkraft_uptown_espresso_kitchen_assembly_video.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d748.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD748 5376 bytes
SHA-256: add5d187b08450771d7310dc297246c5fcc4e5a3dc453cabf82f8017be207fdb
font_01_sfnt_off0000e9a3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE9A3 10616 bytes
SHA-256: 75435ac2db866c8e58043a24bd5b1cce6218238b503f75dce17711209c8b1dee