Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7567a9e8f353f62…

MALICIOUS

PDF

66.9 KB Created: 2021-03-15 07:55:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5b7e410e4976c125c7e4258ade23d81 SHA-1: 99b3b0f8fde04ba3094be0960c781481aa897d72 SHA-256: c7567a9e8f353f62e791573f8eb09a0d7422e94bdad2ebf604dc0e29dbffa79a
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL `https://druttle.ru/strik?utm_term=brick+rocket+stove+design+guide` is a primary indicator of a phishing or malware distribution attempt, disguised as a 'brick rocket stove design guide'. Although no scripts were explicitly extracted, the PDF structure and heuristic firings suggest it's designed to exploit vulnerabilities or redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9603

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/strik?utm_term=brick+rocket+stove+design+guide
    • http://nesorus.mywebcommunity.org/bukuvenanijotirilu.pdf
    • https://cdn-cms.f-static.net/uploads/4483589/normal_6026bc88442da.pdf
    • https://cdn-cms.f-static.net/uploads/4467601/normal_602e21487fefd.pdf
    • https://static.s123-cdn-static.com/uploads/4386073/normal_5fc5bc5446071.pdf
    • https://cdn-cms.f-static.net/uploads/4485176/normal_60359b806703c.pdf
    • https://cdn-cms.f-static.net/uploads/4445555/normal_6016c2c950535.pdf
    • https://cdn-cms.f-static.net/uploads/4449766/normal_6047d9f5badaa.pdf
    • https://cdn-cms.f-static.net/uploads/4475853/normal_6045fc3c807b0.pdf
    • https://static.s123-cdn-static.com/uploads/4403680/normal_600840b3e76ec.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/174963c8-18a1-404c-9ae5-9d4b49bb0e27/spore_cd_key_generator.pdf
    • https://uploads.strikinglycdn.com/files/d2aeced4-12e4-4a93-b744-8a51a9948922/why_is_my_washing_machine_saying_sud.pdf
    • https://uploads.strikinglycdn.com/files/dbd2e698-5807-456f-b509-d36b8cc686c0/xawamuvo.pdf
    • https://uploads.strikinglycdn.com/files/94517c0e-0ee0-4ce4-9456-46a17e2acf6c/polska_szkola_w_naperville.pdf
    • https://uploads.strikinglycdn.com/files/96358436-502b-42f3-b27b-b547c2f26b63/rancilio_silvia_espresso_machine_used.pdf
    • https://s3.amazonaws.com/zamuriza/misifumanubinawu.pdf
    • http://bekusisit.atwebpages.com/adobe_captivate_2021_release_date.pdf
    • https://s3.amazonaws.com/toliwudalamem/allomorphs_in_english.pdf
    • https://s3.amazonaws.com/jadudusujuje/69470675392.pdf
    • https://uploads.strikinglycdn.com/files/0c7cb4f4-df4d-41c7-9d64-7d09ad7d8655/xanugaxobudiwowete.pdf
    • https://s3.amazonaws.com/pujirageg/6205857374.pdf
    • https://s3.amazonaws.com/widiku/hl7_cda_certification_study_guide.pdf
    • https://uploads.strikinglycdn.com/files/e54e7852-b538-446a-9b41-20302217130a/how_to_reset_drum_counter_on_brother_printer_hl-2270dw.pdf
    • https://uploads.strikinglycdn.com/files/ef9e214d-c29f-4f86-ba68-fefafdc200a3/how_to_draw_a_heart_with_pencil.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fa63.bin
8739fdebbc85bbbe9262b737466c4fdb3597f07edefada7cea1ecfb133deb56e
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA63 5036 bytes