Malicious PDF — malware analysis report

Static analysis result for SHA-256 702733de80956676…

MALICIOUS

PDF

67.3 KB Created: 2021-03-09 22:42:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8d386d238bb9bff11c2612daf41f5510 SHA-1: 230984af34aec75eeacaf6ff87da780f6802c7b7 SHA-256: 702733de8095667620c2244861d5c6c620fc66efacc4c7c71516e6f7f71d295d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying it as a link farm. One prominent URL, 'https://resalured.ru/strik?utm_term=singular+and+plural+nouns+ppt+presentation', suggests a deceptive lure related to a presentation. ClamAV detection and ML classification further confirm its malicious nature, likely as a phishing or trojan delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=singular+and+plural+nouns+ppt+presentation
    • https://cdn-cms.f-static.net/uploads/4387244/normal_604061ca96f20.pdf
    • https://fadefewili.weebly.com/uploads/1/3/4/3/134316521/7bd03.pdf
    • https://cdn-cms.f-static.net/uploads/4462992/normal_600ea0937faf4.pdf
    • https://static.s123-cdn-static.com/uploads/4482206/normal_5feb574505f0a.pdf
    • https://menekagamop.weebly.com/uploads/1/3/4/0/134097565/5581958.pdf
    • https://jesofoxera.weebly.com/uploads/1/3/1/4/131407857/fc3970cb7aa.pdf
    • https://xudekumuf.weebly.com/uploads/1/3/2/6/132681038/74c853b4ae74.pdf
    • https://cdn-cms.f-static.net/uploads/4501810/normal_603a624823222.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/992ad8bd-b017-4fea-b484-ae400a9ae3e5/how_to_get_tracfone_my_account_app.pdf
    • https://uploads.strikinglycdn.com/files/f84adf92-04c0-4cdf-921e-69ca4c5cc5a0/journey_to_the_west_movie_fish.pdf
    • https://uploads.strikinglycdn.com/files/b55d74c9-9eb2-4b47-bdbe-413371625af3/horse_dog_hybrid.pdf
    • https://c78267de-509c-4cb0-9394-6b21b7876e04.filesusr.com/ugd/290ce3_403282692bd84be8bf326c42ee8a4d8f.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b54ef8f3-c7d8-43bb-98fa-30a85debff14/gadamer_truth_and_method_download.pdf
    • https://uploads.strikinglycdn.com/files/97247b3b-646c-463d-84af-e61797b6d8fd/58844731513.pdf
    • https://uploads.strikinglycdn.com/files/685b1eb8-8313-49ab-b7fa-e445c48fb7d9/what_are_african_musical_instruments.pdf
    • https://uploads.strikinglycdn.com/files/7b4dcc72-2454-47f2-80bf-fcffa96c8937/tesufugaregisunol.pdf
    • https://uploads.strikinglycdn.com/files/1cba8ce1-984d-4953-9381-296a83cfbcf5/les_misrables_2012_rating.pdf
    • https://d1159ab4-cbf5-42eb-897b-83a5e94cd7da.filesusr.com/ugd/536122_808c1bc23683430e9ea4450e011027d4.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c8a5058f-c013-4684-9270-bdf96353afcf/theseus_and_the_minotaur_hades.pdf
    • https://uploads.strikinglycdn.com/files/b20b1866-53f6-4bae-a65f-bc0116a8b437/percy_jackson_and_the_olympians_disney_plus.pdf
    • https://uploads.strikinglycdn.com/files/374affd8-ee69-481d-b6ed-86e766926866/brother_5450dn_toner_reset.pdf
    • https://uploads.strikinglycdn.com/files/dade7066-7d61-4602-969c-aaa290f75269/best_brand_of_fridge_to_buy_in_malaysia.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cb6b.bin
2573462ace6004d17d32f52ef842105246949117c7732402d199ffc9eb5aca41
pdf-font-stream PDF embedded font (sfnt) at offset 0xCB6B 5228 bytes
font_01_sfnt_off0000dd3f.bin
219f2eb6a992d1e0b65e15ec980cb212b6d3e4200e63d70de67ce77aa552f511
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD3F 9768 bytes