Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b2a3f88d69b1f72…

MALICIOUS

PDF

88.9 KB Created: 2021-04-04 08:59:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 852cd9984eae979d6b92cc44f5734be4 SHA-1: b1e61bb1c9e453f63e69929c6aa0bb9470acb267 SHA-256: 0b2a3f88d69b1f72f1aa2886321730cc02fcb6b1e582f5d3de103d922e11e6bd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to 'zajinet.ru', which is likely a phishing or malware distribution site. The document body, though heavily obfuscated, suggests a lure related to a 'recipe book'. No scripts were extracted, but the PDF structure and embedded URI are strong indicators of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=the+reboot+with+joe+juice+diet+recipe+book+pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4dcecd0d-3f31-4b3f-a45a-f012be4b1c81/48444969164.pdf
    • https://uploads.strikinglycdn.com/files/0e9224f6-8e86-4644-b110-04251b1120ac/mupowebigupulagaxo.pdf
    • https://uploads.strikinglycdn.com/files/4d7a2915-34a7-446b-98df-d577a5562466/17569495273.pdf
    • https://uploads.strikinglycdn.com/files/2e4446b3-7c8a-4b04-b7a3-9c4d26879d68/45566518087.pdf
    • https://uploads.strikinglycdn.com/files/59dfe81e-2407-497b-9354-7cd1e835b03b/lizizavoxilami.pdf
    • https://s3.amazonaws.com/dapekufoxiraku/specific_learning_disabilities.pdf
    • https://uploads.strikinglycdn.com/files/948b4360-c0b2-496d-9122-9b74dd21071a/rebof.pdf
    • https://uploads.strikinglycdn.com/files/7ad13d84-2f3e-42e9-95f8-fd066bde0bb9/thank_you_mr._falker_lesson_plan.pdf
    • https://s3.amazonaws.com/sewamos/donotapodopedetofol.pdf
    • https://s3.amazonaws.com/xotomisen/34771636652.pdf
    • https://s3.amazonaws.com/tevigotu/what_can_adobe_acrobat_standard_2017_do.pdf
    • https://s3.amazonaws.com/gofilafixu/wisawimavo.pdf
    • https://uploads.strikinglycdn.com/files/dc48ff2d-2b52-4b0a-8e73-5554cb4b54d7/pippi_longstocking_movies_list.pdf
    • https://s3.amazonaws.com/juliziwojatige/how_to_get_graphic_design_certificate.pdf
    • https://uploads.strikinglycdn.com/files/30548594-8f3e-4546-a1fa-8495e5b2d5fc/35427872376.pdf
    • https://uploads.strikinglycdn.com/files/d7371a85-260a-43e0-8ae6-ff661ff6e854/how_to_reset_a_honeywell_scanner.pdf
    • https://s3.amazonaws.com/jobavo/dixoj.pdf
    • https://s3.amazonaws.com/wegugus/linksys_connect_setup_software_wrt54g.pdf
    • https://s3.amazonaws.com/nijudow/29936107207.pdf
    • https://s3.amazonaws.com/tugabijenovili/garirasivofux.pdf
    • https://s3.amazonaws.com/punagilelabon/22793689435.pdf
    • https://s3.amazonaws.com/fidefofudi/deadpool_2_motion_picture_soundtrack.pdf
    • https://uploads.strikinglycdn.com/files/847f1eae-a2e9-4bde-8488-185ea7b3e74f/91499996817.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011b68.bin
26539a9f2bab631119f82c1cc452fc35c4eeb66213d1641edb22542361713ac8
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B68 5144 bytes
font_01_sfnt_off00012cf7.bin
8262ce5d8a94a0c5f9f4e179296782d73c32769efa1650f479a16e19db0945a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x12CF7 11524 bytes