Malicious PDF — malware analysis report

Static analysis result for SHA-256 90c825d8e590ccfd…

MALICIOUS

PDF

82.4 KB Created: 2021-03-29 03:28:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c4e62540b110100e776a05dc3c934bfe SHA-1: e455d74253e5911533789127b3eb6bc73dc9bbce SHA-256: 90c825d8e590ccfd2df5e7c098b54cae89416c479e214a432dbcadaf60e14c69
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various URLs. One prominent URL, 'https://resalured.ru/strik?utm_term=how+do+animals+store+excess+energy', is directly embedded and flagged as an external URI. ClamAV also detected this file as 'Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0', strongly suggesting a phishing or malicious intent. The ML classifier output of 0.999208 further supports the malicious classification.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=how+do+animals+store+excess+energy
    • https://cdn-cms.f-static.net/uploads/4457876/normal_602aec0e2e9ab.pdf
    • https://static.s123-cdn-static.com/uploads/4492593/normal_5fdcb86d7639d.pdf
    • https://static.s123-cdn-static.com/uploads/4387922/normal_5fe4577220db0.pdf
    • https://cdn-cms.f-static.net/uploads/4426819/normal_6014d58d27d41.pdf
    • https://xelewutoritawi.weebly.com/uploads/1/3/1/0/131070131/565c01def151f94.pdf
    • http://rrrrkkkkk.space/favubosuuzso.pdf
    • http://winoorama.site/2015_audi_q7_maintenance_manualghnxj.pdf
    • http://trickyturkey.com/toveziretovwkr7o.pdf
    • http://floradoma.net/umbrella_academy_apocalypse_suite_download2x249.pdf
    • http://wisitens.online/microsoft_word_format_painter_shortcut_keynqoqr.pdf
    • https://mirajaxudedina.weebly.com/uploads/1/3/0/7/130775596/tonoxajipu.pdf
    • https://static.s123-cdn-static.com/uploads/4404976/normal_5fca4abf35070.pdf
    • https://static.s123-cdn-static.com/uploads/4480149/normal_5ff260b6bf150.pdf
    • https://ponuwusareti.weebly.com/uploads/1/3/1/6/131636782/redufuda-tusadigogud.pdf
    • https://cdn-cms.f-static.net/uploads/4422373/normal_603542fa9199e.pdf
    • https://cdn-cms.f-static.net/uploads/4487647/normal_601117dcc58ee.pdf
    • https://folodekoj.weebly.com/uploads/1/3/2/8/132814523/jogalutugefinud.pdf
    • https://romevezijije.weebly.com/uploads/1/3/4/7/134756673/aa6cbc23.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f34565a9-3828-4e0f-b700-2f7cb9d85060/what_type_of_oil_for_gy6_150cc.pdf
    • https://uploads.strikinglycdn.com/files/b9b13bd1-b6c4-43c5-9658-3013e0b7fcbd/a_discovery_of_witches_season_2_episode_8_recap.pdf
    • https://uploads.strikinglycdn.com/files/301800fb-61d6-4081-a477-bdbb6fafbd0c/rmv_drivers_permit_application.pdf
    • https://uploads.strikinglycdn.com/files/dcd47466-33eb-4a53-90b2-a11175ea0302/92984128886.pdf
    • https://uploads.strikinglycdn.com/files/f5773173-4fa5-4b5b-bc9a-0f884aacdce7/how_to_setup_vizio_36_2.1_soundbar.pdf
    • https://uploads.strikinglycdn.com/files/7bc38ea3-5e10-4eee-ba2a-202c45a7a2b8/vozabojimakudo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010248.bin
fa3955cd28cfdce08963c1bca15f698c66dc11e832856a3e0e1772c83457bfe7
pdf-font-stream PDF embedded font (sfnt) at offset 0x10248 5480 bytes
font_01_sfnt_off000114eb.bin
bac53d61b383da054bced1259c5252e27548bd10ed58fc9b920c007dbd933729
pdf-font-stream PDF embedded font (sfnt) at offset 0x114EB 11648 bytes