Malicious PDF — malware analysis report

Static analysis result for SHA-256 d43ead5175c3de67…

MALICIOUS

PDF

82.2 KB Created: 2021-01-13 11:41:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: cf543d0169b3138832ce878e4f9cc17b SHA-1: 79325d21c404b447488645548b1fc5ee9766b72d SHA-256: d43ead5175c3de6723c9b3c39578fe305e7a5a9780ced484e303c421f9b73b1b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URI pointing to a suspicious domain, trafftec.ru. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. The document body, though heavily obfuscated, contains text fragments that may relate to search results or document sharing, supporting the phishing lure attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/123?utm_term=trolls+google+drive+2016 PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4481168/normal_5fad8b01730a0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417653/normal_5f96d2a02b02f.pdfIn PDF document text
    • https://cdn.sqhk.co/jutafegobexe/jhscjcZ/mcintosh_speakers_xr14.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4474727/normal_5fbd04dc635fb.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jivuxo/dubufefi.pdfIn PDF document text
    • https://s3.amazonaws.com/mufukep/91420265578.pdfIn PDF document text
    • https://s3.amazonaws.com/zarusegibitumet/kugul.pdfIn PDF document text
    • https://s3.amazonaws.com/bejideba/kokefovekagebigefe.pdfIn PDF document text
    • https://s3.amazonaws.com/nafibanefexex/glossary_of_educational_psychology_terms.pdfIn PDF document text
    • https://s3.amazonaws.com/lunojol/cydia_apk_file.pdfIn PDF document text
    • https://s3.amazonaws.com/baritexovopa/alternatives_to_google_play_store_for_android.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea5e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEA5E 5272 bytes
SHA-256: 7afcda44e375dc344d8457b4d012cb459266fcca3f0d26ece4bd0bf91bdf18b2
font_01_sfnt_off0000fc6d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC6D 10832 bytes
SHA-256: 8ba830364b89357080c86f0e2c46f98ddb1daa98ca045841a6dcf6041239a2d9
font_02_sfnt_off00012159.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12159 17120 bytes
SHA-256: c238f55d4d1f125060ad265c1290cdc091298375134cd8a1bd8b5c54bfa34a63