Malicious PDF — malware analysis report

Static analysis result for SHA-256 5296fcf8d81196ee…

MALICIOUS

PDF

85.1 KB Created: 2021-04-26 21:59:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: d4f4ff62b033cb0c3d0f402f6c040c89 SHA-1: 2b655c8447fca200becffff49993a6cc67c91948 SHA-256: 5296fcf8d81196eec2dfda0e75f35a54614b1368aad4cbce9f9742824a9ac73c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with a primary malicious URL identified as 'https://resalured.ru/strik?utm_term=how+to+set+up+total+gym+platinum'. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting a link farm for SEO manipulation or malware distribution. ClamAV detection and ML classification strongly indicate malicious intent, likely phishing or a trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=how+to+set+up+total+gym+platinum PDF link annotation
    • https://mokenexub.weebly.com/uploads/1/3/4/4/134478104/8374223.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470231/normal_60439b8952590.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4503791/normal_6004b63adc3d8.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4474220/normal_5fd1c2b0644bb.pdfIn PDF document text
    • https://vogaxuruxav.weebly.com/uploads/1/3/4/3/134352923/8673500.pdfIn PDF document text
    • https://kibanelamuvudu.weebly.com/uploads/1/3/0/9/130969844/mofasagidewimakiwozu.pdfIn PDF document text
    • https://gemujofu.weebly.com/uploads/1/3/4/3/134372819/95334.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372707/normal_606197f49c987.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/3224bed4-e289-4321-80b0-40d983d2001e/wuvasenujedosat.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/347c77f6-4862-4f64-995c-53c9a28b2548/panasonic_telephone_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5c121078-b614-48c8-9fd9-396d059976ee/sistema_politico_mexicano_libro.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3aa74352-9b23-419d-8993-bf0804b6953b/17546146538.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b6c60663-93b4-43ae-8305-1d547d4bafaf/mr._coffeer_cafe_barista_bvmc-ecmp1000_espresso_maker.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6c75919c-35e2-41aa-88b8-a567627cd7ff/44534333047.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b1eea79-a855-4b50-91ae-b95c5c988ddb/guitar_licks_in_g_major.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b8569234-7784-4efc-973f-f7fef7e031d3/how_to_fix_my_shark_navigator_vacuum.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b072f8d-7ffd-4465-b067-8952be200f4b/how_to_reset_an_iphone_4_that_is_disabled_without_a_computer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3cf486ea-7c65-4769-8633-c9a47fac1471/88317487716.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/489f1a20-d0a1-478a-864f-bdf6116a62e4/26446082016.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/69384488-385a-4245-8f83-d339a3be8d47/how_many_watts_to_charge_milwaukee_18v_charger_use.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/660a3c75-5738-403c-8304-889294e51258/41591154495.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/803f3da1-e63c-4a7e-a0e1-758e63c5f1c9/zibajejope.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/80ede863-fe72-4b9d-88dc-a1ee4d9271c1/which_is_better_gentle_leader_or_halti.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010cbe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10CBE 5200 bytes
SHA-256: 4b2b4866300db65ca8ef532d98311c61de5739896a408280c221db0ca878a876
font_01_sfnt_off00011e7a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11E7A 11360 bytes
SHA-256: 24a45b94104b7c81889fabc2d86e77f53d3409ba4b9ede8e0f225167ea8432d8