Malicious PDF — malware analysis report

Static analysis result for SHA-256 4cb9d960e7861704…

MALICIOUS

PDF

84.8 KB Created: 2021-04-18 12:57:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b0d9aafca886306ec52158847b25c1ae SHA-1: 16782dd19f1487ccf1a0cac4d4f6e8ac0f09a74c SHA-256: 4cb9d960e7861704c50103928f25d74e12cb02e9e4d618e3db782b3ce9a82605
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains multiple embedded URLs, one of which, 'https://kuzutuzo.ru/strik?utm_term=worx+16+inch+electric+chainsaw+reviews', appears to be the primary lure. While no scripts were explicitly extracted, the presence of embedded URIs and the nature of the detection suggest an attempt to redirect the user to a malicious site, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=worx+16+inch+electric+chainsaw+reviews
    • http://suzamakulamuj.mypressonline.com/sub_zero_refrigerator_parts_model_642.pdf
    • https://cdn.sqhk.co/ragejeli/eji4jaU/wvu_car_stickers.pdf
    • https://cdn.sqhk.co/letijefa/hjiagg7/god_kings_game_cheats.pdf
    • https://cdn.sqhk.co/tejosepu/icihjjQ/disneyland_paris_deals_2021.pdf
    • https://cdn-cms.f-static.net/uploads/4485434/normal_60415dfb3c675.pdf
    • https://cdn-cms.f-static.net/uploads/4388174/normal_602b8587b607f.pdf
    • https://cdn-cms.f-static.net/uploads/4485800/normal_5fe7b566e697c.pdf
    • http://topsalon.xyz/61595815760rimr6.pdf
    • http://mpvideo.org/the_culture_map_chapter_3_summarywyox9.pdf
    • http://pasetbs.xyz/britax_pavilion_70-g3_replacement_cover1qeby.pdf
    • http://vixegoxufareka.getenjoyment.net/nizetabuk.pdf
    • http://operationhomeplate.com/61602558078kgan8.pdf
    • http://bristol-yalta.run/704182360680tacu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6f8cb219-4830-455d-9ced-b55e65700e85.filesusr.com/ugd/fd30ac_0500297d99e64a1192070d0c448f3422.pdf?index=true
    • https://fac30f9c-1bc3-4ff6-ac40-7ced1d2a170b.filesusr.com/ugd/3b7182_e292315411c147428ce444035a4f3a78.pdf?index=true
    • https://caa91486-5fcc-43b7-8b2b-5b817ae85bbe.filesusr.com/ugd/26bbcf_5a924ffe34f54841bd012353f0010a14.pdf?index=true
    • https://6ba8113a-99dc-4618-97bf-d7180f10ff72.filesusr.com/ugd/b6edda_f1ca3f6e0af840c9becc943994abee7b.pdf?index=true
    • https://2ed821ec-8078-4e74-b11b-c5cec6a88262.filesusr.com/ugd/65e777_e0617b4673fa46589ebc0f9c337096bd.pdf?index=true
    • http://zejibanunepi.myartsonline.com/ssc_stenographer_2020_question_paper.pdf
    • http://nibopinalilabaj.onlinewebshop.net/linajes_y_blasones_de_galicia_del_padre_crespo.pdf
    • http://wewamamewiler.atwebpages.com/dofufarifavazubagabugibo.pdf
    • https://uploads.strikinglycdn.com/files/f445da97-5241-4367-990b-53111f457ce4/27832089977.pdf
    • https://uploads.strikinglycdn.com/files/1fbb2436-5534-44bc-a36e-b5cffd9f9499/42883151535.pdf
    • https://uploads.strikinglycdn.com/files/16186db3-13bc-4e57-a2cb-f458b2d5b6a4/texuvufemes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010e48.bin
f0e72514b321f44fa26129437e3c9a6ddd16fcccd5c7f513c4fe95c4c42f34e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E48 5324 bytes
font_01_sfnt_off00012088.bin
ff5f948b8a5ecb3294e82e7b7b9b93ebe1cab908c6043a6e619e61b9e5fc9e19
pdf-font-stream PDF embedded font (sfnt) at offset 0x12088 10864 bytes