Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe193617d22bec69…

MALICIOUS

PDF

57.3 KB Created: 2020-11-10 04:46:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 61c2e808950a6220cb0a22544c70ed14 SHA-1: e30a8c2b11161fa78ea7adad0a68c8345df7b9a5 SHA-256: fe193617d22bec69b3d876cd39f01d286e2a43df53247779510d6839b8c63f91
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL 'https://trafffi.ru/strik?keyword=the+machine+shop+burbage' suggests a phishing or credential harvesting attempt. While no scripts were explicitly extracted, the PDF structure and embedded URIs are commonly used for delivering malicious content or redirecting users to exploit kits.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9704

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?keyword=the+machine+shop+burbage
    • https://popilezofale.weebly.com/uploads/1/3/1/1/131164236/wogajag.pdf
    • https://cdn-cms.f-static.net/uploads/4378378/normal_5f8a42c5a8d4e.pdf
    • https://bofufawikifof.weebly.com/uploads/1/3/4/2/134235483/5f6af82.pdf
    • https://cdn-cms.f-static.net/uploads/4386094/normal_5fa83e070d815.pdf
    • https://cdn-cms.f-static.net/uploads/4449170/normal_5fa32dde48ba4.pdf
    • https://cdn-cms.f-static.net/uploads/4369503/normal_5f8a9cc7d19f6.pdf
    • https://cdn-cms.f-static.net/uploads/4375195/normal_5f95d4692f4e1.pdf
    • https://cdn-cms.f-static.net/uploads/4366017/normal_5f9d180e71a7c.pdf
    • https://fulugive.weebly.com/uploads/1/3/0/8/130874350/2922085.pdf
    • https://xufuledinidud.weebly.com/uploads/1/3/4/6/134645490/4828609.pdf
    • https://zitidatuviwe.weebly.com/uploads/1/3/4/4/134493200/morabojikigip-nosuwotepegug-fivafonigexoxoz-vofujosivono.pdf
    • https://witorovi.weebly.com/uploads/1/3/4/6/134643219/doloto.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c8ece57a-1976-4307-8e68-b11dd3b706b7/fukisozemisovilisagoxefe.pdf
    • https://uploads.strikinglycdn.com/files/8b33a5ef-a42d-4b61-9fe3-178763b95bc4/eureka_vacuum_cleaner_manual.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b70a.bin
8d40f511f3dd63ebc1cf5bdbf46a8ebe4e92ffb3119640f0f9cfb10a4c9c9af0
pdf-font-stream PDF embedded font (sfnt) at offset 0xB70A 5204 bytes
font_01_sfnt_off0000c87b.bin
c95d7d8b36a3120c324b046224ad91ced37702b85c7d09d5961367f5fd7f4757
pdf-font-stream PDF embedded font (sfnt) at offset 0xC87B 9968 bytes