Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b37c6842cbab486…

MALICIOUS

PDF

78.2 KB Created: 2021-03-28 11:37:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 96415a47d912b686ad30df289af8899d SHA-1: 23353df8614d9697900cb38abf55d0e607d1b4ae SHA-256: 5b37c6842cbab48625251a9b4cb0978f726fc4b01633997ff9d8a1a1148e1882
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by ClamAV as Pdf.Phishing.Trojan and by an ML classifier as malicious. It contains an embedded URI pointing to 'kuzutuzo.ru', which is likely part of a phishing or malware distribution scheme. The PDF structure and embedded content suggest it's designed to trick users into visiting a malicious external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=what+is+examples+of+figurative+language PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4481173/normal_5fcdac7669e85.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4458631/normal_6030ea1b59b39.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4498978/normal_5fed16db51eff.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413838/normal_60253a6d3b391.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4392862/normal_5fd37cb1567c4.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4490265/normal_6008e05b732a4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4427293/normal_602a71bbf11a8.pdfIn PDF document text
    • http://wafixevewitope.mypressonline.com/23162866453.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4488806/normal_604580838172b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451737/normal_60559e9f8d1bb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450003/normal_602a720a421b4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408989/normal_600bb28e64673.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369334/normal_6048a3213846b.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/2fd89932-da2e-4abe-8de5-4043e89ba55d/alphatrak_2_test_strips_petsmart.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e092d872-f43a-4c22-8986-fa9b409bc9a3/dyson_v7_absolute_user_manual.pdfIn PDF document text
    • http://daluzijirajof.rf.gd/traducir_archivo_de_aleman_a_espaol.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bb2087c0-dabb-46e8-ad02-6ea651ef4eae/dadonaxujabovavudoziw.pdfIn PDF document text
    • http://labimovoguduwej.epizy.com/98954060246.pdfIn PDF document text
    • http://diwavubodinaroj.myartsonline.com/27331883115.pdfIn PDF document text
    • http://lefamuredemupi.epizy.com/fraction_multiplication_worksheets_6th_grade.pdfIn PDF document text
    • http://falowowujozaba.rf.gd/asymmetric_information_theory.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3301a6c3-565d-4346-86fa-961cf01d8254/pabetukuvavafalav.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1e1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF1E1 5456 bytes
SHA-256: c1e7fe0053fe455a44776066cd6227596947635c8b3b71e03794786d941c58a1
font_01_sfnt_off0001045d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1045D 11480 bytes
SHA-256: 945dc90e734770d6d02b318a9304b73b5f3cc5cca9cdb7d854cfffd6765629ab