Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b001dea3891c30b…

MALICIOUS

PDF

86.7 KB Created: 2021-03-23 01:05:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e977a5a74989a618679f4af8f502761e SHA-1: 496e6c7bec46b99e3bd868ad42d7049d1795d273 SHA-256: 7b001dea3891c30bb38513100ed4c672981881bee99c176c395ed9b1beae061a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are designed to appear as legitimate documents but lead to a link farm. The primary malicious URL identified is resalured.ru, which is likely used to host or redirect to further malicious content. The ML classifier strongly indicated maliciousness, and the PDF structure suggests an attempt to manipulate search engine results or lure users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/award?keyword=black+widow+comic+pdf
    • https://silavetej.weebly.com/uploads/1/3/5/3/135314504/kixajalujovejasisa.pdf
    • http://kagaromorin.medianewsonline.com/linipojufusibagodi.pdf
    • https://static.s123-cdn-static.com/uploads/4505159/normal_600024f49578a.pdf
    • https://lojefumelo.weebly.com/uploads/1/3/0/8/130814401/lufaro.pdf
    • https://muwegejise.weebly.com/uploads/1/3/4/2/134265646/ragakukiki.pdf
    • https://gumijunu.weebly.com/uploads/1/3/5/3/135399233/e71b08f.pdf
    • https://cdn-cms.f-static.net/uploads/4405638/normal_602bf66446a07.pdf
    • http://vizazovabula.mywebcommunity.org/88580635854.pdf
    • http://pusapev.scienceontheweb.net/nonlinear_functional_analysis_and_its_applications_i_fixed_point_theorems.pdf
    • https://static.s123-cdn-static.com/uploads/4383138/normal_5fdd48ae3ca3a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/b0f9a05e-5143-4292-9c46-9d1edff8274c/what_is_a_manufacturing_trade_deficit.pdf
    • https://uploads.strikinglycdn.com/files/788f9b1a-caab-4284-9338-17a6dd27f680/does_ipod_touch_get_ios_13.pdf
    • https://s3.amazonaws.com/sevoga/lotizazidotuxunorag.pdf
    • https://s3.amazonaws.com/mafavuzenoliki/descargar_imagen_iso_windows_7_ultimate_32_bits.pdf
    • https://uploads.strikinglycdn.com/files/3aedbf86-5772-4147-9e9a-4094d7e07e17/tabela_fator_de_correo_inss.pdf
    • https://s3.amazonaws.com/xifabilejilab/baldwin_mi_weather_report.pdf
    • https://uploads.strikinglycdn.com/files/ef70d54a-876f-4854-aa46-275c6168403c/5276751188.pdf
    • http://rurebafib.onlinewebshop.net/nimijijosame.pdf
    • https://uploads.strikinglycdn.com/files/648d727f-7c49-4b4a-883b-28a9c3e24bff/are_metal_roofs_loud_when_it_rains.pdf
    • http://kageditivumimor.onlinewebshop.net/eduardo_galeano_el_libro_de_los_abrazos_gratis.pdf
    • https://s3.amazonaws.com/vazisi/apple_music_history.pdf
    • https://s3.amazonaws.com/fizaxo/harry_potter_germany_2019.pdf
    • https://uploads.strikinglycdn.com/files/d0935e7a-a39e-4f4a-a189-b03505a2a80d/free_willy_3_streaming_ita.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f641.bin
2262e0dee26a7d346fd7404300ffef88aee91c522a3580c52a131eb96737b83e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF641 5232 bytes
font_01_sfnt_off0001080e.bin
8627510ad825a5932f28f37a2916e4ee2de3152b3515f434046631ed4fd11e10
pdf-font-stream PDF embedded font (sfnt) at offset 0x1080E 2272 bytes
font_02_sfnt_off00011263.bin
c4546f4afd79a04584093f67a34b0276c26add956cec0acc1935780ed20e91dc
pdf-font-stream PDF embedded font (sfnt) at offset 0x11263 11416 bytes
font_03_sfnt_off00013887.bin
52db30b66cfb76898988bc7c6ed152514c301740808ab95bec9c68e49df23550
pdf-font-stream PDF embedded font (sfnt) at offset 0x13887 16036 bytes