Malicious PDF — malware analysis report

Static analysis result for SHA-256 60dfef18c6c0f84c…

MALICIOUS

PDF

74.2 KB Created: 2021-06-07 16:26:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bcd178baa866004430fa94b4353c2093 SHA-1: 225c6830f1aa8570f2a652269caad7bf686d432a SHA-256: 60dfef18c6c0f84ce01ad377c6b35e556ca2a13a485d86faaf12f4622dcc6974
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URL pointing to 'crysiq.ru', which is likely the phishing destination. The document body, though heavily obfuscated, contains references to 'Winnie the Pooh 1926 pdf' and authoring information suggesting it's a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crysiq.ru/pbw?utm_term=winnie+the+pooh+1926+pdf
    • https://jokazetesolibut.weebly.com/uploads/1/3/5/3/135314514/7b06ce3b6ab46.pdf
    • https://fewurigog.weebly.com/uploads/1/3/0/9/130969621/fcd4f04.pdf
    • https://cdn-cms.f-static.net/uploads/4383452/normal_602b6181cfb23.pdf
    • https://cdn-cms.f-static.net/uploads/4474998/normal_5fe7cb7076853.pdf
    • https://cdn-cms.f-static.net/uploads/4423431/normal_606043b168a63.pdf
    • https://tufizesux.weebly.com/uploads/1/3/4/5/134596030/c8e16173.pdf
    • https://cdn-cms.f-static.net/uploads/4450354/normal_6041562a4ddfa.pdf
    • https://cdn-cms.f-static.net/uploads/4461511/normal_603cc2411ff24.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://mefijunov.pbworks.com/w/file/fetch/144414783/real_book_bass_clef_free.pdf
    • http://lulimogosan.pbworks.com/f/free_retrenchment_letter_template_south_africa.pdf
    • http://dowiginade.pbworks.com/f/kavoxufudub.pdf
    • http://pudamalulera.pbworks.com/w/file/fetch/144751041/26317106054.pdf
    • http://lipadune.pbworks.com/w/file/fetch/144412788/photosynthesis_worksheet.pdf
    • http://jetipufagi.pbworks.com/f/gta_5_rp_glitch_2019.pdf
    • http://ragasegena.pbworks.com/w/file/fetch/144792588/how_do_you_calculate_voltage_drop_in_ac.pdf
    • http://feteselulo.pbworks.com/w/file/fetch/144610116/circumference_of_a_circle_worksheet_7th_grade.pdf
    • http://nubuzefi.pbworks.com/f/pebugevadejixulakopu.pdf
    • http://jesababa.pbworks.com/f/peso_molecular_de_la_plata.pdf
    • http://gobujirewod.pbworks.com/f/5408255776.pdf
    • http://dipoziw.pbworks.com/w/file/fetch/144439515/38089232020.pdf
    • http://xetibubib.pbworks.com/w/file/fetch/144580479/what_chapter_is_aot_season_4_episode_15_in_the_manga.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e456.bin
6acd492764d4be5e54eace2b4619574500dea5062c7dd94b97cf9a0a34070295
pdf-font-stream PDF embedded font (sfnt) at offset 0xE456 5120 bytes
font_01_sfnt_off0000f5df.bin
01678ea2ce34add317d9f35540d1176f6bd6fccccaaa131dcf91c95a2bee0198
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5DF 11092 bytes