Malicious PDF — malware analysis report

Static analysis result for SHA-256 71144ae67ef8765a…

MALICIOUS

PDF

76.0 KB Created: 2021-04-08 00:18:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 18e8216bfb63c5f3479d5afd64e7c5d7 SHA-1: 0f72d058d4d621980dec74fb232cf8c05387869a SHA-256: 71144ae67ef8765ae4851e84f70a44d0c929d8eb0a690c4389cb23f51b9684c2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to 'resalured.ru', which is likely the malicious destination. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest an attempt to redirect the user to a harmful site, possibly for phishing or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=audacity+insert+silence+at+start
    • http://kexejadupuna.66ghz.com/florida_state_map_template.pdf
    • http://sujatafuluwariv.22web.org/kewugapedokuwavoxekax.pdf
    • https://cdn.sqhk.co/kivipemo/hhjdhid/43068504625.pdf
    • https://cdn.sqhk.co/fekawifen/bzjijg4/pesipaxesexaloxirava.pdf
    • https://cdn.sqhk.co/guwuweri/ajeBheW/ufc_253_results_sanchez.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/abe9ea29-4e11-4ebe-b1b4-c78cf5e1b2c2/54742153520.pdf
    • https://87deab66-c645-46c6-955a-dbc2758d34a6.filesusr.com/ugd/302fc9_0d5c13b83fe84ba39ac99bd59b00d289.pdf?index=true
    • https://s3.amazonaws.com/zetituri/78788584146.pdf
    • https://0491f86b-060d-4f4a-be23-b0d01488777f.filesusr.com/ugd/faa7ef_dad5d001b854485dbe50925055cc98c4.pdf?index=true
    • https://9305c775-266c-4126-9ef9-90a5cffee957.filesusr.com/ugd/c3f88d_d1bd51ffe81c422685b9935ff97e8ac0.pdf?index=true
    • http://gonidiwofove.epizy.com/casio_privia_px_330_user_manual.pdf
    • https://uploads.strikinglycdn.com/files/ba36793d-f0d8-459d-96b6-87a51de9d4e3/45841913231.pdf
    • https://63995da9-74be-4895-8497-a4fa53c9845d.filesusr.com/ugd/788c84_29649771ee7f466cb287a2b328023498.pdf?index=true
    • https://b913155d-2712-4fd4-bcc6-651970a8c456.filesusr.com/ugd/e39924_5d899be8219748b7bfecb8c96f5f389d.pdf?index=true
    • https://75e6d08a-b14f-4c2c-bd4e-3e6431d9d11c.filesusr.com/ugd/497a87_1c77da716c1c4e3e9904758e8ce30931.pdf?index=true
    • https://s3.amazonaws.com/nevowimo/89938477445.pdf
    • https://6cda4dd4-8aac-43e7-8003-7c0eea9f7907.filesusr.com/ugd/34e26e_c3933a9177054d158479030b97522253.pdf?index=true
    • https://29c5b005-6627-40e3-9da1-9f9d3dbc34dc.filesusr.com/ugd/7ad284_1a3cfef7cf454742a9ac0ae22eebdf89.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec7b.bin
0c725dfb92478431691090776d97a110b56cdbe0f8d6899a6fe5ddc6c9129bde
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC7B 5024 bytes
font_01_sfnt_off0000fda6.bin
efc88853424f507c0d410acc650fe318332fe3c94b73eee93d7bfd2938bd60ae
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDA6 10996 bytes