Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fcb397bd155f43e…

MALICIOUS

PDF

75.5 KB Created: 2021-03-10 11:46:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 2911716104fa17b6bfe3683b828dfcf8 SHA-1: daab164a8dedb60ad086c6e761cec4811e872805 SHA-256: 1fcb397bd155f43e44892208e3c8bb1eac3ef88ca845f24c1cc200347fef98fe
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for link farms or phishing campaigns. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URL 'https://resalured.ru/wix?keyword=fun+doodles+to+do+when+your+bored' is likely part of the lure to direct users to a potentially malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=fun+doodles+to+do+when+your+bored PDF link annotation
    • http://krepezh.guru/navujusedurcun0y.pdfIn PDF document text
    • https://cdn.sqhk.co/waladoved/dihsxWm/gatemipor.pdfIn PDF document text
    • http://3-bureaureport.info/american_gangster_game_free_for_pcsj4j0.pdfIn PDF document text
    • http://gnoogle.site/flannelette_sheet_set_single_bedp4vp4.pdfIn PDF document text
    • http://ro-shop.space/14665297028idetk.pdfIn PDF document text
    • https://cdn.sqhk.co/remigalakefo/gihfibx/to_do_list_microsoft_office.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://a7563df4-ba19-4d82-a8a0-b2470d957038.filesusr.com/ugd/61f964_5e1579aab688491fa72fc30789f73678.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/8a5aa51b-e08e-430a-b42a-efde8f31c5ca/97244908500.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a599749c-fc1a-45a4-8734-d57bdbcda718/soxulubilumomare.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/29039071-d3df-4f90-9d42-038f5785b508/how_to_make_money_playing_online_poker_tournaments.pdfIn PDF document text
    • https://01d7ec8a-e38e-4e33-8c76-1be31754498b.filesusr.com/ugd/24d943_bb298b54737046a9aa0b0119d977b38f.pdf?index=trueIn PDF document text
    • https://78905da9-dd21-4190-abaa-c894c042e703.filesusr.com/ugd/851c7c_cf668d27bc124656b224bf995d102430.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e2fbe6d-a0f6-4164-bfa3-4f2f3dd6a5da/18815371700.pdfIn PDF document text
    • https://07e0a16e-b77d-475b-b724-88bbaedb347c.filesusr.com/ugd/8e9e2f_bae3db1c70f14efda454e7de580a49be.pdf?index=trueIn PDF document text
    • https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_ec6693587df84e1b9e565bd0c5f5eac7.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/5f91ed9e-8c1a-420e-9f43-9df28d82ed49/foloxiruporeri.pdfIn PDF document text
    • https://b354d503-40d1-4c97-84b4-bc0b16c12f35.filesusr.com/ugd/8c7d07_04018be20ea1409984594a56f59843e0.pdf?index=trueIn PDF document text
    • https://80b2a579-f9ed-4aa0-b91a-ac3c8973c086.filesusr.com/ugd/353d00_564ef52bc7344807aee95509a22843d4.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/b8d7be2f-2bff-4596-841c-2b5d50d85949/what_do_birthday_wishes_mean.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d8cf08d3-f73d-4871-a080-704002e34620/xepepepagefasus.pdfIn PDF document text
    • https://40e214c1-1950-44e8-a195-e2c6eeb23253.filesusr.com/ugd/a517f4_2fa23e3b64b4410ba8954679aa1e83ff.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/6331d9ef-4b24-4ecf-aacf-1247c561e3d0/java_8_stream_api_map.pdfIn PDF document text
    • https://6a421494-2577-4416-904f-e17348f56b63.filesusr.com/ugd/85e76a_d66b0961958d41f3b49c2c344ab656dd.pdf?index=trueIn PDF document text
    • https://37bcb4aa-7747-4ff6-a352-0e22bf983c21.filesusr.com/ugd/4393d3_3389979e24a043faa5a69e44a95d80a1.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ecab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xECAB 4992 bytes
SHA-256: f0d3badb8c698fddb8a09a4944fa910d32ef10c3228f3ee9618845c2b527a782
font_01_sfnt_off0000fdb3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDB3 9996 bytes
SHA-256: b53aec6c7d780488fa2e76914040de06d34c7c6247f6b5f1660bb7d1878555c2