Malicious PDF — malware analysis report

Static analysis result for SHA-256 dca66c7a98379ff4…

MALICIOUS

PDF

73.5 KB Created: 2021-01-17 12:07:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 367627aef39cbb2d29ac147c25b419ea SHA-1: 77fd465cb8afa0ed80dd0489b5bf1d4dbefdcf63 SHA-256: dca66c7a98379ff48e7feaa2359cb96b7dc3477d0b293211361d5b08a8e0a79e
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of an external URI pointing to 'traffnew.ru' suggests a phishing or malware distribution attempt. The 'SE_URGENCY_LURE' heuristic further supports the phishing pretext by indicating the document contains language designed to prompt immediate action. No scripts were extracted, but the PDF structure itself likely facilitates the malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/aws?utm_term=callmecarson+crying+next+to+joe+swanson+template
    • https://jufigewadekuxo.weebly.com/uploads/1/3/1/4/131406441/9180644.pdf
    • https://site-1176636.mozfiles.com/files/1176636/train_sim_world_2_xbox_one_controls.pdf
    • https://site-1175031.mozfiles.com/files/1175031/pay_express_toll_e470.pdf
    • https://kominalekawer.weebly.com/uploads/1/3/1/6/131636772/gefopugojodewe.pdf
    • http://molipetofokeva.22web.org/keystone_species_worksheet.pdf
    • http://bofesota.66ghz.com/excel_bedingte_formatierung_formel_text_enthlt.pdf
    • https://levalezekavazif.weebly.com/uploads/1/3/4/6/134639406/ramebuzi-vaximubul-gazidig.pdf
    • https://ratisajaruniz.weebly.com/uploads/1/3/1/4/131455275/7578343.pdf
    • https://vusukiziroge.weebly.com/uploads/1/3/0/9/130969505/6574949.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/gurowozenupifi/50659447191.pdf
    • http://xonukekavufimil.epizy.com/45395007793.pdf
    • http://bovifuxabobi.epizy.com/3622673589.pdf
    • https://s3.amazonaws.com/datarofapakil/feature_creature_worksheet.pdf
    • http://roxegubipav.epizy.com/chai_latte_k_cups_nutrition_information.pdf
    • https://s3.amazonaws.com/sirasu/super_mario_maker_2_yamamura.pdf
    • http://bojibag.epizy.com/kms_activator_windows_10_2018_free.pdf
    • https://s3.amazonaws.com/jefobexapulow/axillae_singular_form.pdf
    • http://zuvetimimu.rf.gd/iphone_airplay_android_box.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ca65.bin
d2261e2ad87e3e8cb85e0e2d113ee5970ed89a8bd477a4b6c38568574114d4e4
pdf-font-stream PDF embedded font (sfnt) at offset 0xCA65 5404 bytes
font_01_sfnt_off0000dcc2.bin
8c5f596b751b5df4f2110414aaa1c630b67d90a9bc37611b1def66c0a15a082c
pdf-font-stream PDF embedded font (sfnt) at offset 0xDCC2 2060 bytes
font_02_sfnt_off0000e65b.bin
32e3a4013b024fe39b9d17238a883bb6e2ed784139fa1bba6b3e4de3cfe2c251
pdf-font-stream PDF embedded font (sfnt) at offset 0xE65B 10540 bytes
font_03_sfnt_off00010a18.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A18 4324 bytes