Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9f07ba87a636192…

MALICIOUS

PDF

92.8 KB Created: 2021-03-21 21:03:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fd0f206492f524f8aa87555f7a43e49a SHA-1: 5bda5b9859ba321188792ce1eee1695f0b3ffe51 SHA-256: d9f07ba87a6361923f307ee591c71d957db8a7b3b540ba091b830cfa88699f52
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as phishing-related. It contains an embedded URI pointing to a suspicious domain, 'kuzutuzo.ru', which is likely part of a phishing campaign. The document body, though heavily obfuscated, suggests a lure related to academic syllabi.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=b+pharm+1st+year+syllabus+2020+pdf
    • http://zuduwamani.mypressonline.com/kewavexixujuzobefezaxato.pdf
    • https://cdn.sqhk.co/rujiwujik/QljbgfY/fast_key_launcher_app_download.pdf
    • https://cdn.sqhk.co/makekajet/hhgZHgb/rubube.pdf
    • https://cdn.sqhk.co/visukodo/iigfIib/84262054737.pdf
    • http://mamubisuk.mypressonline.com/gosewigofudiwus.pdf
    • https://cdn.sqhk.co/kavatupopum/jfiaaie/armaan_malik_new_tamil_songs.pdf
    • http://femonejigajape.mywebcommunity.org/was_the_book_of_enoch_in_the_original_canon.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kizugokofo/cardioversion_farmacologica.pdf
    • https://s3.amazonaws.com/mipeboro/fobofiwefirarufof.pdf
    • https://uploads.strikinglycdn.com/files/769e671a-77ea-44b0-8cc4-ccc139be2975/poluxurokuperivawufi.pdf
    • https://s3.amazonaws.com/xirixepo/real_survival_battle_royale_squad_mobile_apk.pdf
    • https://uploads.strikinglycdn.com/files/03de0544-0674-4bd2-90d1-195f6a44cee7/columbus_blue_jackets_schedule_printable.pdf
    • https://s3.amazonaws.com/lorugipopuxe/learning_java_programming_with_eclipse.pdf
    • https://uploads.strikinglycdn.com/files/d23775e3-36f7-4722-90c2-2213a3c39681/rofelavemijixajofudok.pdf
    • https://uploads.strikinglycdn.com/files/48b4ca1c-1012-4c6f-a986-c94eb92977c3/3396013004.pdf
    • https://uploads.strikinglycdn.com/files/fa49f477-2d83-424d-bb4c-b94308e764ed/komagolojavimisetetibule.pdf
    • https://s3.amazonaws.com/lowuwofuxali/is_it_healthy_to_use_a_diffuser.pdf
    • https://s3.amazonaws.com/gagotaniwipure/free_gantt_project_planner_template.pdf
    • https://s3.amazonaws.com/limewub/biblical_meaning_of_numbers_1-_1000.pdf
    • https://uploads.strikinglycdn.com/files/64323764-0557-4917-81fe-ce9bd20ade1f/schlage_camelot_entry_door_handle_installation.pdf
    • http://todiwefexoneb.atwebpages.com/kixin.pdf
    • http://fijorolur.myartsonline.com/public_speaking_coaching_near_me.pdf
    • https://uploads.strikinglycdn.com/files/cece14cf-e1ff-4c5c-b986-990cbab16cd6/problemas_ambientales_en_mexico_2020.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012921.bin
598fae1ed3191290580bc94c1d3fdbf730d0adb742cdda6a9ce3f21d0d7eb410
pdf-font-stream PDF embedded font (sfnt) at offset 0x12921 5900 bytes
font_01_sfnt_off00013d11.bin
13f5ef0b2550c3bad1aadf69f4b0205fe72ea31ba8c60e2c72fa3ee63f745e36
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D11 11504 bytes