Malicious PDF — malware analysis report

Static analysis result for SHA-256 76b793e2760c39dc…

MALICIOUS

PDF

76.8 KB Created: 2021-04-24 10:00:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a6e24ea59467e6f0ff24dba6c002bc03 SHA-1: 5160fcf256f5546e3a47fb291b88ec6c98804c1b SHA-256: 76b793e2760c39dcd2e469d0609586e7fef2323a1ebeb2a4720ab90885c92596
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying it as a link farm. One of the primary external links, https://kuzutuzo.ru/strik, is flagged as unknown reputation and is likely the intended destination for malicious activity. ClamAV detection and ML classification strongly indicate malicious intent, classifying it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=what+is+the+order+of+the+whatever+after+series
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/78539a98-0eaa-414d-8e0b-4af479f193c6/how_heavy_is_a_580_case_backhoe.pdf
    • https://uploads.strikinglycdn.com/files/f6cfd341-21c2-41f3-bef6-d5ae18a122cb/riraki.pdf
    • https://51fd5013-30c4-43d1-89ce-86564632a3b5.filesusr.com/ugd/9f06f8_f6dc196692644084a9ea84794408831e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/29804854-595d-41e3-a03f-8315b711d1d5/kemalikokawura.pdf
    • https://uploads.strikinglycdn.com/files/6be180d4-5e14-4d56-b390-9d69a958b099/rujopomow.pdf
    • https://uploads.strikinglycdn.com/files/f2e273f4-6bda-4cad-b036-305cdefb4964/bare_bones_a_survey_of_forensic_anthropology_2nd_edition_free.pdf
    • https://uploads.strikinglycdn.com/files/29f0bccc-4a2c-431c-a7e5-22e102b6d87e/fundamental_theorem_of_calculus_integral_calculator.pdf
    • https://uploads.strikinglycdn.com/files/145eaae1-25cb-43ce-8aa6-33d4c1eb846d/47555848496.pdf
    • https://f904ef53-caa1-4f0f-8a97-c50675c03ece.filesusr.com/ugd/2f8cea_4efba69523404da1bfcdfb0728092118.pdf?index=true
    • https://uploads.strikinglycdn.com/files/5f7a0daa-040a-47f4-b1dd-b10067d5b775/8218051537.pdf
    • https://uploads.strikinglycdn.com/files/b95cd128-21cb-4c19-9358-f2bfebd6c2f4/hp_designjet_500_printhead_cover_error.pdf
    • https://uploads.strikinglycdn.com/files/877e474c-59ea-4270-b457-3a7e29ffaaf1/which_portable_air_conditioner_is_the_most_energy_efficient.pdf
    • https://uploads.strikinglycdn.com/files/7fbebe8f-2c05-453a-99a8-d9bee89577bb/rofukex.pdf
    • https://uploads.strikinglycdn.com/files/81f050a0-12b0-4b78-8c14-3dcbf0108ebc/99637383153.pdf
    • https://28ae28a3-27cc-4d38-be83-0de1f6925f83.filesusr.com/ugd/454016_63c21bdce2724e67807acb61bbaae1cb.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e9c65e46-83d8-40f3-abf3-2fd32dae8226/amway_levels_income_2019.pdf
    • https://uploads.strikinglycdn.com/files/bf9bd671-b62f-4326-963a-5a06c736fc52/excel_spreadsheet_templates_free.pdf
    • https://uploads.strikinglycdn.com/files/39567641-4112-4667-bba4-69f598df060a/what_is_gothic_architecture_characteristics.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee7d.bin
b52edec4e8a1dcdb783ccbabe5a021c6fc85d61ab45d905ea8c749b23a4c4e92
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE7D 5128 bytes
font_01_sfnt_off00010006.bin
15fcbab4ea77c6361d6c3cf0e478d6c406a765d1d5b52b9731a14bc4d5c5365c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10006 11192 bytes