Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ec73c1b390a9923…

MALICIOUS

PDF

78.6 KB Created: 2021-03-24 22:22:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d0ea9a2b9355a619f36ea3a39451f00d SHA-1: 105a23f92bb60a2a1d52c2c4c34d90ed799bcd1c SHA-256: 8ec73c1b390a99234b95a813c70f45e6c03cba9cd7f69f21005e55ae5683b813
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://kuzutuzo.ru/strik?utm_term=posing+guide+for+couples+pdf', which is likely part of a phishing or malware distribution scheme. The document body, though heavily corrupted, suggests a lure related to a 'Posing guide for couples pdf'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=posing+guide+for+couples+pdf
    • http://tohld.in/dibujos_con_lineas_horizontales_y_verticales_para_colorearcp3t6.pdf
    • https://cdn.sqhk.co/dazulegug/czzhchc/only_one_of_kpop_wiki.pdf
    • https://cdn-cms.f-static.net/uploads/4465149/normal_6020ab0ed373e.pdf
    • https://cdn-cms.f-static.net/uploads/4416938/normal_6035cf5e8b699.pdf
    • https://cdn-cms.f-static.net/uploads/4388060/normal_5fdac851a579a.pdf
    • https://cdn-cms.f-static.net/uploads/4489835/normal_60391900a0d9c.pdf
    • http://meinekarten.best/ageless_body_timeless_mind_bookzlei1.pdf
    • https://cdn.sqhk.co/pujazojiwixi/f2gcAhT/diners_club_ecuador_direccion.pdf
    • http://zubiki.top/88771806386xj199.pdf
    • http://edevletorg.com/britten-norman_islander_maintenance_manual_download69hp5.pdf
    • http://maewallace.com/wekadebaxukab4up5l.pdf
    • https://cdn-cms.f-static.net/uploads/4385010/normal_604e361079ff9.pdf
    • https://static.s123-cdn-static.com/uploads/4460981/normal_5fddae9e0c420.pdf
    • https://cdn.sqhk.co/letarezetap/jjgcjiX/bluestacks_hd_app_player.pdf
    • https://cdn-cms.f-static.net/uploads/4421468/normal_601d24abcbe0f.pdf
    • http://interstart.online/kifigutomovofala6393f.pdf
    • http://igcopyrightclient.com/turtle_beach_ear_force_px5_pc_setupdeb20.pdf
    • https://cdn.sqhk.co/definuseju/69P7agf/dolakinokeduxanifat.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4e408146-811f-47f3-bb53-2efd4dbf2c84/dakef.pdf
    • https://uploads.strikinglycdn.com/files/ec7748b0-91a3-4e67-95a9-c9d943b9a239/john_mcmurry_quimica_organica_9_edicion.pdf
    • https://uploads.strikinglycdn.com/files/5d37935e-429d-478e-a3c9-04f255c7e323/98315715178.pdf
    • https://uploads.strikinglycdn.com/files/212ccf8c-79f5-4469-a4c9-5517282ed866/why_is_beauty_and_the_beast_the_best_movie.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f61b.bin
0912bc37cece55a1650a8a0de75a1902e3257b2332dde4b959248a6e68a48251
pdf-font-stream PDF embedded font (sfnt) at offset 0xF61B 5116 bytes
font_01_sfnt_off0001079c.bin
479ef2806bdc06518b6a45550164459501b91e4f26c2e967afbd95c3c2096a75
pdf-font-stream PDF embedded font (sfnt) at offset 0x1079C 10628 bytes