Malicious PDF — malware analysis report

Static analysis result for SHA-256 9667b827e2704d28…

MALICIOUS

PDF

77.7 KB Created: 2021-03-16 07:40:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8b248fb09cccd5aa71577de798c58de4 SHA-1: 7a5880dd794590db8bada7b88b4ff9ba80d241f7 SHA-256: 9667b827e2704d28ea93a6af928cfe03d8896dd72ef90ea4a3f2e1686370dc47
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing or malware distribution lure. It contains a large number of external links, many of which are suspicious, including one pointing to 'resalured.ru'. The document body, though heavily obfuscated, suggests a lure related to free audiobooks, aligning with common phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/aws?utm_term=ciaphas+cain+for+the+emperor+audiobook+free
    • https://static.s123-cdn-static.com/uploads/4427504/normal_5fedc3672e71a.pdf
    • http://tigixupog.22web.org/dreamweaver_tutorials_for_beginners_free_download.pdf
    • https://cdn.sqhk.co/totimujid/Ygc74RI/bcg_attorney_search_scam.pdf
    • http://zulurasovuguloz.66ghz.com/18912892271.pdf
    • https://cdn.sqhk.co/virapazetif/hj09Lhh/battle_city_tank_1990_rom.pdf
    • https://cdn-cms.f-static.net/uploads/4465018/normal_5fd627aeef819.pdf
    • https://cdn.sqhk.co/bomumuxa/jtigf2t/guwiralalabomedazisavanol.pdf
    • http://jijufik.22web.org/thank_you_powerpoint_template_free.pdf
    • https://cdn.sqhk.co/fomiroza/jhbiaii/lenovo_moto_smart_assistant_app.pdf
    • https://cdn-cms.f-static.net/uploads/4467927/normal_5fe863257fa6b.pdf
    • https://cdn-cms.f-static.net/uploads/4454045/normal_6044def16fca7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/7d8b936b-8123-4acb-b718-88ca0776ea83/zmodo_dvr_camera_system.pdf
    • https://uploads.strikinglycdn.com/files/aecd5aa2-7e9e-4d20-aec8-3e11abae9d4e/26878587431.pdf
    • https://uploads.strikinglycdn.com/files/d7e161ff-9647-46f3-b456-0bf002187295/hamilton_beach_flexbrew_replacement_carafe_49983.pdf
    • https://945b3f91-9c76-4178-be32-f0dab3cfe2c6.filesusr.com/ugd/8d5d69_e91a3039ec7d436285facb22e241fd21.pdf?index=true
    • http://bigisewolax.epizy.com/blue_cross_insurance_forms.pdf
    • https://uploads.strikinglycdn.com/files/839de9a2-15c2-4bf5-a532-9f89bba9fbf6/photoshop_cs3_software_free_download_for_windows_10_64_bit.pdf
    • https://uploads.strikinglycdn.com/files/3f574bef-06b1-47dd-a3b3-f2f92fc7dc1b/where_is_tintern_abbey_located.pdf
    • https://ddf64d59-5240-4154-9987-17dfc28e22c7.filesusr.com/ugd/cec570_64947afad4644a699a7aed5142a27d61.pdf?index=true
    • http://robatirewixiwol.rf.gd/best_push_pull_legs_strength_and_hypertrophy.pdf
    • https://uploads.strikinglycdn.com/files/7c39ed89-f870-4d64-83a3-312afae37790/14267350244.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee64.bin
a0a4a6a912074fd63c4b0f539015a22f61be3ef2b7f93dccaaa33a3cc85a4510
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE64 5472 bytes
font_01_sfnt_off000100d0.bin
0746d39e54b60c9375cac920caca69e10eb8d20fcf2b261404551da64a5ae8fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x100D0 11292 bytes