Win.Trojan.Print-2 — PDF / .EXE malware analysis

Static analysis result for SHA-256 f4531a3749112820…

MALICIOUS

PDF / .EXE

2.62 MB
MD5: 1c73bbef2e1fa743f48fde70a02b7eb0 SHA-1: 63a3ebcca28f71287fe79fc2ca058cc2344192c1 SHA-256: f4531a3749112820ffc2f736884502f5e8fd3d815c5d8f91afccd9cd49e4675a
76 Risk Score

Malware Insights

Win.Trojan.Print-2 · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The critical ClamAV detection of 'Win.Trojan.Print-2' strongly indicates a trojan payload. The presence of embedded JavaScript and the 'FROMCHARCODE' heuristic suggest obfuscated code execution within the PDF. The numerous unknown-reputation URLs likely serve as command-and-control or download locations for the malicious payload.

Heuristics 4

  • ClamAV: Win.Trojan.Print-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Print-2
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • String.fromCharCode low PDF_FROMCHARCODE
    String.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.oisv.com
    • http://www.dynamicpad.org/
    • http://www.rudenko.com/
    • http://www.rudenko.com/robosoft/upgrade_prog.html
    • http://www.rudenko.com/sites/
    • http://www.asp-shareware.org/pad
    • http://www.wingsofdarkness.net/php/index.php
    • http://illusionaryz.deviantart.com}}}\f2\fs18\par
    • http://www.BoltBait.com
    • http://www.BoltBait.com}}}\f2\fs18\par
    • http://www.dmashton.co.uk/
    • http://www.dmashton.co.uk/}}}\f2\fs18\par
    • http://www.xdp.it/cximage.htm
    • http://www.xdp.it/cximage.htm}}}\f0\fs18
    • http://www.icsharpcode.net/OpenSource/SharpZipLib/Default.aspx
    • http://www.icsharpcode.net/OpenSource/SharpZipLib/Default.aspx}}}\f2\fs18\par
    • http://www.sjbrown.co.uk/?code=squish
    • http://www.sjbrown.co.uk/?code=squish}}}\b\f0\fs18
    • http://www.pinvoke.com
    • http://www.pinvoke.com}}}\f2\fs18\par
    • http://www.oxygen-icons.org/
    • http://www.oxygen-icons.org/}}}\f2\fs18\par
    • http://www.everaldo.com/crystal/
    • http://www.everaldo.com/crystal/}}}\f2\fs18\par
    • http://www.huddletogether.com
    • http://huddletogether.com/projects/lightbox/
    • http://www.macecraft.com/share/lightbox/loading.gif
    • http://www.faqts.com/knowledge_base/view.phtml/aid/1602
    • http://simon.incutio.com/
    • http://www.macecraft.com/images/images-2/arrow.jpg
    • http://www.macecraft.com/images/images-2/header.jpg
    • http://www.macecraft.com/images/images-2/textfield_bg.gif
    • http://www.macecraft.com/images/images-2/tabBgNew.jpg
    • http://www.macecraft.com/images/images-2/user-rating-caption.jpg
    • http://www.macecraft.com/images/images-2/user-rating-body.jpg
    • http://www.macecraft.com/images/images-2/commonbox1-background.jpg
    • http://www.macecraft.com/images/images-2/commonbox1-caption.jpg
    • http://www.macecraft.com/images/images-2/commonbox1-body.png
    • http://www.macecraft.com/images/images-2/commonbox1-foot.jpg
    • http://www.macecraft.com/images/images-2/button1.jpg
    • http://www.macecraft.com/images/images-2/list-icon.jpg
    • http://www.macecraft.com/images/images-2/commonbox2-body.jpg
    • http://www.macecraft.com/ver2/images/emailbox.jpg
    • http://www.macecraft.com/ver2/images/table_heading.jpg
    • http://www.macecraft.com/images/images-2/tabBgNew2.jpg
    • http://mydomain.com/dp/
    • http://illusionaryz.deviantart.com
    • http://www.cs.man.ac.uk/~toby/alan/software/
    • http://www.cs.man.ac.uk/~toby/alan/software/}}}\f0\fs18
    • http://support.microsoft.com/servicedesks/msdn
    +5 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00117a3e.bin
aa200be6d4324263de453df695a258f4a0f764b51a48d1d42ef82a5d1d1e26b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x117A3E 34992 bytes
font_01_sfnt_off0011cb1a.bin
bb467a1c790e72582b417d7fd79ca9f536e5067f5fa6fdc7f620c2d339792a1b
pdf-font-stream PDF embedded font (sfnt) at offset 0x11CB1A 1164 bytes
font_02_sfnt_off0011d04e.bin
33a060a94d55f5f175c301c82e07d1b78ade08759c89e0b7cedb9c353bc6f860
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D04E 37820 bytes