Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ea8d71a2a36df82…

MALICIOUS

PDF

75.1 KB Created: 2021-03-30 22:26:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 21f1c4b5a8d334c9f5c0da5a79a5150c SHA-1: 8ef2a53f1446f7d93a6155a9019ac941829bb172 SHA-256: 8ea8d71a2a36df824204efd75978817c812ea9c73c72aa5310e20c5222c23f74
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to 'https://kuzutuzo.ru/wix?keyword=skyrim+soul+gem+guide', which is likely a lure for phishing or malware download. The heuristic 'SE_INVOICE_LURE' suggests the document's content is designed to trick the user into clicking the link. No scripts were extracted, but the PDF structure itself facilitated the embedding of the malicious URI.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/wix?keyword=skyrim+soul+gem+guide
    • http://logvoz.ru/tedoviwunatemase6lznp.pdf
    • https://cdn-cms.f-static.net/uploads/4412415/normal_602a194d11302.pdf
    • http://tenipimutav.mywebcommunity.org/nicomachean_ethics_loeb.pdf
    • http://recepty-dd.info/44521312211qnmr2.pdf
    • http://rijoginijamibeg.mypressonline.com/service_menu_toshiba_regza_tv_codes.pdf
    • https://cdn.sqhk.co/kagelemovo/hCAyib6/88591138802.pdf
    • https://static.s123-cdn-static.com/uploads/4494668/normal_60013d82708b2.pdf
    • https://static.s123-cdn-static.com/uploads/4379726/normal_600651641439c.pdf
    • https://cdn.sqhk.co/feketukadoz/b8zzmha/cooking_master_boy_2019_streaming.pdf
    • http://leseweremizew.scienceontheweb.net/27377602394.pdf
    • https://cdn.sqhk.co/kazamepa/hPtl4QO/kukip.pdf
    • http://fsfsfd.xyz/medical_surgical_nursing_ignatavicius_10th_edition_study_guideusk7d.pdf
    • https://cdn-cms.f-static.net/uploads/4461509/normal_605fa4c7edaab.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gofiguj/88285899352.pdf
    • https://s3.amazonaws.com/dosipive/27161445782.pdf
    • https://uploads.strikinglycdn.com/files/d49f4ff1-9349-4151-a9a2-3b48e0eb7c29/gituworugokaxigufer.pdf
    • https://uploads.strikinglycdn.com/files/6014f1db-c73b-44b4-bd6b-c706de2708ac/what_is_the_best_book_for_business_studies.pdf
    • https://uploads.strikinglycdn.com/files/28ee92f7-45c8-403e-bc16-9ab77b5b8b0d/the_magicians_season_6_cast.pdf
    • https://s3.amazonaws.com/muxozuvalubi/nordictrack_exp_1000x_specifications.pdf
    • https://s3.amazonaws.com/rujimidujek/mansion_on_the_hill_bruce_springsteen_lyrics.pdf
    • https://uploads.strikinglycdn.com/files/dec8fd4b-a285-46aa-8b56-f775f3a76d08/wavugaramemogozab.pdf
    • http://tavoxelelenasi.onlinewebshop.net/abraham_hicks_the_amazing_power_of_deliberate_intent.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7c0.bin
bc7dc948a69de2b7d92e6cf27d8eedb1b681636560fd839862705c1bdf64f5a0
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7C0 5204 bytes
font_01_sfnt_off0000f968.bin
bdb17e932844239b10a0aaacc237ea6ca5fee7a71f47dc52f4e440a256c69801
pdf-font-stream PDF embedded font (sfnt) at offset 0xF968 11268 bytes