Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9d93a7b81e15fc9…

MALICIOUS

PDF

75.0 KB Created: 2021-03-14 05:26:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 75697c4472db93adafde269474d9acf2 SHA-1: 1e83582b1264c3aba88902b1f6a09c7262ca96f6 SHA-256: f9d93a7b81e15fc92e7827bd5aaa7f1e9bfcb0835fe45c94d8a16b2e0f1b3b1b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, and ClamAV detection confirms its malicious nature. The ML classifier also strongly indicates maliciousness. The document body, though heavily obfuscated, suggests a lure related to 'Kwikset powerbolt 2 customer service' to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=kwikset+powerbolt+2+customer+service
    • http://everydays.space/98219725149c44z5.pdf
    • http://autobuff.xyz/24632020558u17m1.pdf
    • http://amandeepsadyora.com/410325338670eq9k.pdf
    • http://zhenskiizhurnal.ru/63396725438rk5dw.pdf
    • http://toportt.online/ratojorezegevomed1q406.pdf
    • http://navaram.online/67381347733auf6q.pdf
    • http://zeropium.com/guitar_fretboard_notes_wallpapers0gl7.pdf
    • http://vengriya.space/xesazilijafusejn2zxn.pdf
    • http://korecos.ru/namejul1c05z.pdf
    • http://kedisuli.iblogger.org/lubedovofikebepi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://73f4d879-981c-49fe-abc7-520f36a14a84.filesusr.com/ugd/b77b08_6d996fb545a04cbaa82673c14962eab2.pdf?index=true
    • http://zalupadinukoz.rf.gd/aptiom_dosage_forms.pdf
    • https://uploads.strikinglycdn.com/files/acd68c18-574e-42a6-bc1f-c6f7c62c8fdf/the_cambridge_illustrated_history_of_china_2nd_edition.pdf
    • https://e8dc5420-792a-4861-90db-09cfc8d8a7d1.filesusr.com/ugd/1378f5_2e6bc6a0218742e59bd481bf1d4e8e72.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b920386d-1e15-482e-880a-35d1ab744a44/rock_and_roll_snowman_karaoke.pdf
    • https://081e7fb2-604d-424b-9b75-a58d54a71a44.filesusr.com/ugd/abd6ea_bf7a56c6b38244408ead87e5b30e87a9.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e9e21f85-7dca-48df-ae93-464b432aa2dc/cyberpunk_2077_day_one_patch_ps4_size.pdf
    • https://uploads.strikinglycdn.com/files/dd563598-ef12-41a8-9fa8-a0745a9d507e/harry_potter_6_trailer_ita.pdf
    • http://nixemamubefam.epizy.com/what_is_general_purpose_financial_statements.pdf
    • https://3f5765b5-411c-4b28-96d1-a1e3b219bcee.filesusr.com/ugd/ca847e_105972ae6bfd4400845533819c6d7d97.pdf?index=true
    • http://dolipefutulej.epizy.com/akshara_song_badhai_ho_badhai.pdf
    • https://uploads.strikinglycdn.com/files/09548cdc-5292-4d4b-a0d3-b6df39f85521/craftsman_gt6000_lawn_mower_parts.pdf
    • https://a4edf7fa-b057-49b5-8014-e5fd436fbef3.filesusr.com/ugd/c8b2c5_24f545a85cf74e02989143c06ace7617.pdf?index=true
    • https://uploads.strikinglycdn.com/files/5821c206-565f-44cc-a353-a594ae99dc0e/tufinumifagimaginixemol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eaa3.bin
368c3d036d591076a03e14ba11fd10e071db23fd033d3f5b18e48d8671ec71b0
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAA3 5324 bytes
font_01_sfnt_off0000fcc4.bin
203bf945d121c6b12172ac55f57b643c43cfeef127af491b3df2831902598352
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCC4 10052 bytes