Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2467a552f62f9aa…

MALICIOUS

PDF

117.1 KB Created: 2020-12-10 03:00:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 34a3fdbc50c396a25ea1e04f86fce27c SHA-1: 1ccaa16bfa73d4e578edf1f20d4a9c92506b7820 SHA-256: e2467a552f62f9aa90b9dabf5290f2381f401fb8073a6a9842d4d5f1a0fac94e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic indicating an external URI, which points to a suspicious domain 'trafficel.ru'. The ML classifier and ClamAV detection strongly suggest malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URI are indicative of a social engineering attack to redirect users to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?utm_term=adachi+persona+4+voice+actor
    • https://cdn-cms.f-static.net/uploads/4409258/normal_5fb2cdbcec076.pdf
    • https://static.s123-cdn-static.com/uploads/4465403/normal_5fcbf8fbd310e.pdf
    • https://cdn-cms.f-static.net/uploads/4369138/normal_5fa7bcafd7bb0.pdf
    • https://cdn-cms.f-static.net/uploads/4426270/normal_5f9b006adf594.pdf
    • https://cdn-cms.f-static.net/uploads/4382003/normal_5f91ffe5af447.pdf
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9f217e06-a1b8-4b95-8d54-6501805a3f37/gowajitonilufe.pdf
    • https://uploads.strikinglycdn.com/files/3146f643-8caf-48ea-9bb5-2c29ebd5c5a9/ranamaf.pdf
    • https://uploads.strikinglycdn.com/files/1591ab63-77a3-46d9-9509-688ab26f0269/kipixawexedugekagenuka.pdf
    • https://s3.amazonaws.com/befevifa/74361401348.pdf
    • https://uploads.strikinglycdn.com/files/26f8cf6e-e950-4b13-a7df-71f89ef7915a/pomagofosevafovibe.pdf
    • https://s3.amazonaws.com/bupesejirijejus/kjv_study_bible_free.pdf
    • https://uploads.strikinglycdn.com/files/ffdf13d8-5698-431b-881c-f8d47e3b0eed/25083883411.pdf
    • https://uploads.strikinglycdn.com/files/146af416-fdd9-4cff-a713-afd6b24a8658/xolutenif.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00017390.bin
f35cf974a2e0e01f4bd611e3a30a82415e944e7825e5c7368c64fb92f70cb782
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x17390 16012 bytes
font_00_sfnt_off000153c2.bin
77879449a3ee2397c6968859b9f646b8bfcb18c0f3c941b319381a3e1a28e3dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x153C2 3876 bytes
font_01_sfnt_off000161ac.bin
8390b36f9b5f9173fafae8f89eb157348252fb3355ca173e30767da73feb6e85
pdf-font-stream PDF embedded font (sfnt) at offset 0x161AC 5264 bytes
font_03_sfnt_off00019f95.bin
65718056e18dbc851a40f597ba47f4f62c8489e18e764bc8d50add78b0a990b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x19F95 11468 bytes