Malicious PDF — malware analysis report

Static analysis result for SHA-256 ddbb1b1556954595…

MALICIOUS

PDF

100.6 KB Created: 2021-05-11 10:05:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 42e71b8899ebefc16ef38eb913cff304 SHA-1: 98d58b5dcb0705fb42a8584be99ddde4c9166885 SHA-256: ddbb1b1556954595f08807af8cbe989d02c7a001bddcc06c21b6b6a1986a9514
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier with high confidence. It contains an embedded URL pointing to 'kuzutuzo.ru', which is likely part of a phishing or malware distribution scheme. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may be intended to trick users into providing passwords or downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=wd+tv+live+hub+1tb+media+center+manual
    • http://patajafurep.mywebcommunity.org/10965102635.pdf
    • http://bafakuvim.sportsontheweb.net/what_does_the_saying_under_his_eye_mean_in_the_bible.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gapivegek/lelojuwekatijuninewopinur.pdf
    • https://uploads.strikinglycdn.com/files/f6172b99-48bf-49ac-a271-c53ab77f36c5/como_hacer_fotos_artisticas_con_el_movil.pdf
    • http://rawozenagi.epizy.com/warcraft_3_full_game_blizzard.pdf
    • https://uploads.strikinglycdn.com/files/626d2cec-86c2-4953-9516-96979a09313e/muxanolukegili.pdf
    • https://uploads.strikinglycdn.com/files/89b719f1-4635-472d-b881-58eb8a5235cd/what_size_does_brandy_melville_fit_uk.pdf
    • https://s3.amazonaws.com/tevomenil/fizesaboweguxuwesonabor.pdf
    • https://s3.amazonaws.com/rebomedug/software_sign_off_document_template.pdf
    • https://uploads.strikinglycdn.com/files/5823a6a5-98a7-478b-bba6-ab876ad8875c/pufunamisuwigowopubanaguj.pdf
    • https://uploads.strikinglycdn.com/files/ff7ff30b-c6ec-4572-a342-496448ee6da4/what_kind_of_free_time_activities_are_typical_in_your_country.pdf
    • http://timavutiziv.epizy.com/free_color_sheets_unicorns.pdf
    • https://uploads.strikinglycdn.com/files/51ec3273-b4cb-4d19-8bf2-faad259eb914/53447153394.pdf
    • https://uploads.strikinglycdn.com/files/12a94112-3b66-40a5-9073-6284477ebca0/where_is_the_aux_port_in_a_2005_honda_accord.pdf
    • https://s3.amazonaws.com/genijusemu/galaxy_s7_android_9_rom.pdf
    • https://uploads.strikinglycdn.com/files/1d0fcf6e-6bef-4d26-9de1-26a44939e36f/sunebakikimijamaw.pdf
    • https://uploads.strikinglycdn.com/files/7d3927db-b201-4e6e-a123-2301efd5bcef/42569532440.pdf
    • https://uploads.strikinglycdn.com/files/7106a73f-dd09-4793-a204-58f109a4c3a1/zojerume.pdf
    • https://uploads.strikinglycdn.com/files/b12ec39c-9f89-4b85-8b20-863507add63c/3330286268.pdf
    • https://uploads.strikinglycdn.com/files/880e07d8-842e-4dff-8fe5-0e7c09a1edc0/5e_class_tier_list.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014752.bin
9f016871a2c546316c3c3319e557f771cdcc60f3d71d5ca1be2b2c0aaabe8764
pdf-font-stream PDF embedded font (sfnt) at offset 0x14752 5268 bytes
font_01_sfnt_off0001591f.bin
fb387f3d0d789abf0ee07fdd2b94ada9a689ec0c591ab0fbe8cde57472fa8b0b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1591F 12716 bytes