Malicious PDF — malware analysis report

Static analysis result for SHA-256 d7b8bbddc66fcc71…

MALICIOUS

PDF

60.2 KB Created: 2020-12-24 10:39:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 64355a72600e9b39a6d1c61d3f31ed5b SHA-1: bbafa46691d46cbcab2e517a69cbb117d4aa1831 SHA-256: d7b8bbddc66fcc7124ce69292fc91973b4a3de9ae292cbadbdbb9a3caa756566
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL pointing to 'traffking.ru', which is likely part of a phishing or malware distribution scheme. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the overall detection suggest the document is designed to trick users into visiting a malicious site, potentially for downloading unwanted software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9974

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/123?utm_term=showbox+apk+for+roku+stick PDF link annotation
    • https://maviruwatibifiw.weebly.com/uploads/1/3/4/4/134490209/marupaguze.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408704/normal_5fa70b5dea157.pdfIn PDF document text
    • https://jikesekija.weebly.com/uploads/1/3/4/3/134367489/8131998.pdfIn PDF document text
    • https://mawubisevidezo.weebly.com/uploads/1/3/4/4/134480432/juretodo_tujunibugodu_wivoniwunoxubij_jitenokowurepep.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/470c82f1-0439-442f-b3ea-7fdd79a2eee7/journey_across_time_online_textbook.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1f55635-f73e-455e-8db3-1f5d50c13a0b/vimuwuwofasulevexu.pdfIn PDF document text
    • https://s3.amazonaws.com/divelikubapiwaj/wosejavavaluz.pdfIn PDF document text
    • https://s3.amazonaws.com/mesotodimus/jiggin_with_jordan_age.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/86d68c6f-5a56-4609-93b5-91bbe386f3a3/hustlers_dvd_release_date_deutschland.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a71e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA71E 5196 bytes
SHA-256: 2fb2bfadb32f4e304523bf5376f99fb2e74b510cfbe90c7148dfb1dc9c4c188f
font_01_sfnt_off0000b8ee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB8EE 8700 bytes
SHA-256: 5d97ad6ebf8b2266122f16970844401043439078ede86de0715e75b2ab335665
font_02_sfnt_off0000d69e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD69E 4324 bytes
SHA-256: b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c