Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce26498cf18f7a92…

MALICIOUS

PDF

64.5 KB Created: 2020-11-11 14:04:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a2ef2eeace21c0cfa9f0f5fc51e51b90 SHA-1: 57b95be826a7f4a31c43ff9f7bc5b7ae0f529a77 SHA-256: ce26498cf18f7a923a623e3b40e785c483410c640412f84507fc670d8df2aa45
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that redirects to a suspicious domain, likely as part of a phishing or credential harvesting attempt. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to trick users into visiting a malicious site, potentially leading to further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/123?keyword=fried+banana+pepper+recipes+in+the+oven
    • https://cdn-cms.f-static.net/uploads/4420235/normal_5f9ede86787dd.pdf
    • https://cdn-cms.f-static.net/uploads/4412161/normal_5fa8dcf6362dc.pdf
    • https://cdn-cms.f-static.net/uploads/4454289/normal_5fa4afbd45fe2.pdf
    • https://cdn-cms.f-static.net/uploads/4373261/normal_5f8de41d76776.pdf
    • https://cdn-cms.f-static.net/uploads/4367646/normal_5fa8bab61103a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/mubemutolewe/aganglionic_megacolon.pdf
    • https://s3.amazonaws.com/jotizifime/18436637853.pdf
    • https://s3.amazonaws.com/zifozujiwi/kebip.pdf
    • https://s3.amazonaws.com/faluzotixupi/sacramento_to_las_vegas_flights_southwest.pdf
    • https://s3.amazonaws.com/nazekisigiduz/72403819762.pdf
    • https://s3.amazonaws.com/xakapudakadu/17601823875.pdf
    • https://s3.amazonaws.com/ladojenefe/aa_meetings_in_davis_county_utah.pdf
    • https://s3.amazonaws.com/tetazino/assessment_for_learning_b._ed.pdf
    • https://s3.amazonaws.com/bokelur/guxamitagufonuxepibumus.pdf
    • https://s3.amazonaws.com/muvemasoxaji/auto_glass_repair_iowa_city.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bf04.bin
edde732ac25dd4c92b670915fcdfead7bb88b785106582ea7788c0136c2e3bb6
pdf-font-stream PDF embedded font (sfnt) at offset 0xBF04 5284 bytes
font_01_sfnt_off0000d0fa.bin
8fb889765834e294093613c25aa7ae2ae5c4c86b1a5ae5b5f9ccd92cb70e496f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD0FA 10552 bytes