Malicious PDF — malware analysis report

Static analysis result for SHA-256 dceaf0b9fc51a426…

MALICIOUS

PDF

72.0 KB Created: 2020-12-19 11:30:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: ea75a0014a9759b65674e5c1b54c31ce SHA-1: ba7d3289588e6d60af6d0de8422f9a13330bd3b1 SHA-256: dceaf0b9fc51a42668554ab763f34a1252da70d566fac625a5294f52d2464156
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to 'trafffi.ru', which is likely malicious. The document body, though heavily obfuscated, suggests a lure related to educational material, consistent with phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/aws?utm_term=physical+science+grade+12+study+guide+caps PDF link annotation
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/waxegatulo/58394106131.pdfIn PDF document text
    • https://s3.amazonaws.com/pugomonapoxuxe/wii_u_bricked_format.pdfIn PDF document text
    • https://s3.amazonaws.com/xeropizuwe/muvutusagomatawiwov.pdfIn PDF document text
    • https://s3.amazonaws.com/bewibiwat/jevolitotivivofukojelatu.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc59785d49dd12447543100/t/5fd0f0b865fd59770172c08c/1607528633708/21372673302.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc1a859ab79f442f22ef377/t/5fcaff2285bc3a28a6028956/1607139108988/defender_car_price_in_canada.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc573d3bf71053ccb2e5777/t/5fd136b3bf104a7ed86e7202/1607546547774/73241940727.pdfIn PDF document text
    • https://s3.amazonaws.com/kovozenamofox/guide_law_firm.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fdcb77cc464b41678cc2762/t/5fdcee39c6aaff4176dfa327/1608314430741/63246005247.pdfIn PDF document text
    • https://s3.amazonaws.com/rekorewexidiwo/faxufepozubegawugowiru.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc14df88ef7301f8b137930/t/5fca882ddc508f02501dee09/1607108654379/my_talking_tom_angela_download_apk.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdf12a3f75b166439a2fe5/1606283569568/letter_of_ambition_eagle_scout.pdfIn PDF document text
    • https://s3.amazonaws.com/werowibovezoje/feedback_sheets_for_training_sessions.pdfIn PDF document text
    • https://s3.amazonaws.com/salosibejodod/61679762243.pdfIn PDF document text
    • https://s3.amazonaws.com/dorulusof/cheaters_prayer_chris_martin_free.pdfIn PDF document text
    • https://s3.amazonaws.com/zunaduxa/85607173257.pdfIn PDF document text
    • https://s3.amazonaws.com/nalifij/lagu_batak_arvindo_asa_martua_ho.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cc88.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCC88 5396 bytes
SHA-256: 4e6d56e9ab17964709442a399d64f8b4e56b9ea4f7b99e2d177a7835124b32de
font_01_sfnt_off0000dec9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDEC9 11096 bytes
SHA-256: afdca4bb8a44b2ef169c77ca13e814c9ad64d6329f5d1b6481910d7c643f2569
font_02_sfnt_off00010483.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10483 4324 bytes
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176