Malicious PDF — malware analysis report

Static analysis result for SHA-256 13dfe37ad334fa69…

MALICIOUS

PDF

103.0 KB Created: 2021-03-27 18:33:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0d3295e78f8d9e3cfe6b51677358ffd0 SHA-1: 550fd8c42ba47b09b156cc215313a38e2efb616b SHA-256: 13dfe37ad334fa690eafd862e657dd7b3febec0ba03060678b52af06052dbdf0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a "link farm", with the primary malicious URL being https://resalured.ru/strik. This suggests the document is designed to manipulate search engine results or redirect users to potentially harmful content. No scripts were extracted, but the presence of numerous external links points towards a phishing or SEO manipulation tactic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9794

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=more+than+average+meaning
    • http://dominis.xyz/how_to_become_a_forklift_mechanic0pxlb.pdf
    • http://wubufusimeveve.22web.org/kairosoft_bonbon_cakery_mod_apk.pdf
    • https://xapovakugad.weebly.com/uploads/1/3/5/3/135393008/4bf402.pdf
    • http://jamotovoxut.mywebcommunity.org/alternative_careers_in_science.pdf
    • http://zekifafeter.scienceontheweb.net/types_of_blood_groups.pdf
    • http://reduslimitaly-official.site/6648398228602pjd.pdf
    • http://pifedalune.medianewsonline.com/96527068129.pdf
    • http://trendmobile.ru/mechanical_engineering_average_salary_london2vqd6.pdf
    • http://dkblogin-de.best/sales_follow_up_call_script_template0o9uk.pdf
    • https://jusodizepo.weebly.com/uploads/1/3/1/0/131070216/ffb9ebccc3c.pdf
    • https://xivunububan.weebly.com/uploads/1/3/0/9/130969166/zuputesulo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.opentle.org
    • https://6baea7ca-81e4-4a11-8410-716433a99462.filesusr.com/ugd/764aaa_a5a8352491614f02a3271478e8d28338.pdf?index=true
    • https://104e0e48-a4c2-4a03-8647-06ef64d4e6ac.filesusr.com/ugd/e2c6c1_644ee680fb534514a142703c2f5e57bf.pdf?index=true
    • http://wejajesenopezoj.onlinewebshop.net/open_country_sportsmans_kitchen_food_dehydrator_and_jerky_maker.pdf
    • http://jajoditad.rf.gd/14597092869.pdf
    • https://7be8961d-effb-4c78-a255-78c3c9f0be09.filesusr.com/ugd/3dd68e_5ffd611ac61c4a46a570e43a5a29a3a2.pdf?index=true
    • https://b9a4c3d6-4ccf-4d04-9b0f-c2e9c357e15d.filesusr.com/ugd/e5cbe5_720719d082e04e81b8c9730242a3bb11.pdf?index=true
    • http://vogilidiniluti.rf.gd/tuvukas.pdf
    • http://budobilososuw.rf.gd/89015284260.pdf
    • http://romakilax.myartsonline.com/african_american_history_workbook.pdf
    • https://cb2d4818-2134-4ea5-ae57-1bc45cfc4292.filesusr.com/ugd/7e787c_31f427b6299e4670be5f30bcf288243c.pdf?index=true
    • https://72dfff08-f6cb-4f5d-aaac-ebe71175d6a6.filesusr.com/ugd/c268f7_fed0cd9c9f4c4457bbdda647b8152d54.pdf?index=true
    • https://fc06435f-e709-4c80-b59d-96fa470c1a13.filesusr.com/ugd/bdc04d_0f662512d67f434b93b75afcd53ddf2c.pdf?index=true
    • https://97783159-ced7-426e-9fbd-60d2bb3342fb.filesusr.com/ugd/00058f_af534627795f4c97a76891580c703d6d.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off0001607c.bin
65d0e924153896c1b7b934558699ce6804b3861996bb96593d2dc5bc149281ef
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1607C 18176 bytes
font_00_sfnt_off0000dc18.bin
d3fbc2a6a4fefc37a8df4181ca695c97b565794bfcd4acc81fa050f6b49be61d
pdf-font-stream PDF embedded font (sfnt) at offset 0xDC18 5684 bytes
font_01_sfnt_off0000eff5.bin
791c4abc06bc2952807043c487fcbe0c2b8f08e6e4dd4b862d11ced9270867d3
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFF5 4956 bytes
font_02_sfnt_off000100b8.bin
a37cda85596f57e6059ac1f1313d2f33c9be92add6fb1ab1e12a556d9deccb5f
pdf-font-stream PDF embedded font (sfnt) at offset 0x100B8 2656 bytes
font_03_sfnt_off00010bbe.bin
45e304c212156e29fe3879e373e8c4d4eb7f7558b9b507d9aa917d89ddd5a3bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BBE 2328 bytes
font_04_sfnt_off00011672.bin
bbcb7bd70734be4a31c6bf9508418ed7110da018ae6e7a12fcb8c363b0124794
pdf-font-stream PDF embedded font (sfnt) at offset 0x11672 2108 bytes
font_05_sfnt_off0001203e.bin
c109aae36edda875fd35f15f31e7bb6a895eb8195fac0819136039d196d3ef6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1203E 6640 bytes
font_06_sfnt_off000131dd.bin
feb08a23e4af9ea08a78775def246db6deed973b808053681e24cb3bacfaf552
pdf-font-stream PDF embedded font (sfnt) at offset 0x131DD 15708 bytes
font_08_sfnt_off00017d45.bin
379adbff4fd5162a8f290427eb02f808b8dbf03e384c40c5922da2d3f31055e9
pdf-font-stream PDF embedded font (sfnt) at offset 0x17D45 3276 bytes